Valid as of 1 June 2022

1. What does this Privacy Policy tell you?

This Privacy Policy tells you how we collect and process the information from which you can be identified directly or indirectly (“Personal Data”) while you browse www.tikisports.in.th as well as when you interact with our different platforms, portals and applications using your Personal Data.

This Privacy Policy provides information on:

  • Tikisports Data Controllers;
  • Data Protection Officer;
  • the different types of Personal Data we use;
  • why and how we use your Personal Data;
  • how long your Personal Data is kept;
  • other recipients of your Personal Data;
  • transferring your Personal Data out of the country; and
  • your rights under the Personal Data Protection Act B.E. 2563 (A.D. 2019) (“PDPA”) and applicable law.

2. Who are the Tikisports Data Controllers?

These are the Tikisports Data Controllers responsible for protecting your Personal Data and complying with PDPA and national legislation governing the use of your Personal Data. They jointly determine how your Personal Data is used by Tikisports for the purposes identified in the Tikisports Privacy Policy:

  • WeSUP (Thailand) Co., Ltd.

3. How can you contact the Data Protection Officer for the Tikisports Data Controllers?

The Local Data Protection Officer for the Local Selling Entity may be contacted at usa@star-board.com

The Global Data Protection Officer for the Tikisports Data Controllers identified at Section 2 may be contacted at usa@star-board.com

4. What Personal Data does Tikisports collect and use?

These are the categories of Personal Data we collect directly or indirectly from you:

Identity information – includes: name [first, last, initials], Date of Birth, e-mail address, unique consumer identifier number (including your Tikisports membership number), nickname, username, password, social media identifiers and information passed along to us via your Facebook, your device fingerprint, and gift card codes that are assigned to you. We use it to verify your identity.
Contact information – includes: your phone number, shipping and billing address, e-mail address, Messenger ID, social media handle, any other communication channel you have used to contact us for more information. We use it to contact you for different reasons depending on the purposes stated below.
Location information – includes: your residential location, current log-in location [IP address], GPS location (if you wish to share us, for example through your mobile device settings), or the specific Tikisports site you have visited that might give us clues about where you are. We use it to help you find what you are looking for at your current location.
Size information – includes: shoe size, clothes size, height, weight, chest, waist, hip, inseam, body shape, heel-toe measurement. We use it to make sure your gear fits.
Purchase information – includes: your payment information (credit card number), payment risk profile (provided to us by our payment risk solution), shopping cart (your ordered items), delivery details, shipping and billing address, customer order number, purchase history with Tikisports, transaction ID, and any other information related to your purchase. We use it to complete your order on Tikisports sites and apps, in Tikisports stores, or other selling platforms.
Behavioural and Profile information – includes: your shopping history, Wishlist items, your browsing behaviour, your browsing preferences, your shopping preferences, in-store interactions, your workout history, product reviews, social media interactions with us, and any other intelligence we have about you to help us learn you as a consumer better, including “Community information”. We use it to know you better as a consumer, so we can send you marketing messages containing only products and services that we think you might be interested in.
Community information – includes: information provided by you when you participate in various Tikisports events and communities either as a trainer, team member, a participant or as a promoter of our events, including for example: pictures, videos, your nickname, your team, your interests and preferences, your feedback, leader boards, event participation, joined groups, and registration details. We use this information to organise the events and communities, and to know more about you as a consumer.
Social Media information – includes: information obtained through your interaction with us on various social media channels such as Facebook, Instagram, Google, etc., including: any social media information that is publicly available such as your social media handles, social media interactions and public postings, your “Likes” and other reactions, your social media connections, your photos that are public, or those you send to us by mentioning us or following our social media posts by using “handles” or “hashtags”. We obtain this information from the social media network (e.g. Facebook, Snapchat, Instagram, etc.) directly or indirectly through third-party agencies we have agreements with.
Device information – includes: Information about your device or browser that give us an idea about your browsing behaviour or device usage. Your device information is collected by our app, and your browser information is collected by our cookies, tags, and pixels. This is often required for network security purposes. This includes, but not limited to: IP address, date and time of the visit, how long you remained on our website, the referral URL (if you came to our site via a different site or an advertisement), the pages visited on our site, your browser type, device type, versions, operating system.
Activity information – includes: fitness data (for example workout start and end times, activity type, sports category), sensor data (for example step goal, duration, pace, distance, calories, heartbeat, RunScore and speed), and other data related to your fitness app (for example Tikisports Running and Training apps). We use it to help you improve your performance goals and improve your user experiences and identify what products might be best for you based on your exercise patterns.
Correspondence – includes: conversations we have when you contact our Customer Service, the emails you write to us about our products or services, the complaints you address to us via post, e-mail, fax, or call, notes we prepared on your feedback, call back from our Customer Service to you, and any other communication between you and Tikisports personnel/service providers. We record all Customer Service calls for quality assurance purposes.
Preference information – includes: preferred language, log-in location, Wishlist items, preferred shipping address, browsing preferences, our correspondence with you, your Tikisports product reviews. We use it to give you convenience when you visit and/or shop on our sites and apps.

Tikisports information – includes: Unique Member Identifier (member ID), date you became a member, store ID (if you signed up in a retail store), source ID, country and brand of your original membership, membership points, engagement history, rewards history, membership vouchers associated to members. All the information the listed here will be kept for as long as you are an Tikisports member.

 

5. What does Tikisports do with your Personal Data and why?

Tikisports collects and uses your Personal Data for various purposes.

In this section, we explain:

  • When and Why do we need your Personal Data?
  • What do we do to your Personal Data for each Purpose (“Processing”)?
  • Which of your Personal Data do we need for each Purpose (“Categories of Personal Data”)?
  • How long do we keep your Personal Data for each Purpose (“Retention Period”)?
  • With whom (types of service providers) do we share your Personal Data to achieve the purpose (“Categories of Recipients”)?
I. SITE (Tikisports DOMAIN) OPERATION AND APP OPERATION
PROCESSING To run the sites that are connected to the Tikisports domain and the Tikisports app, fix bugs to make sure you always see the site the way we intended, and monitor compliance with our Terms and Conditions, we screen all traffic to our site and analyse data that is received by our servers.

Use of Cookies/Tags/Pixels: We may collect your personal details for this purpose by using technologies such as cookies, pixels and tags to collect your device information. More information is available in “XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES”.

CATEGORIES OF PERSONAL DETAILS Device information

Identity information

Behavioural and Profile information

Preference information

RETENTION PERIOD Browsing Session

We need your data for as long as you are on the site. We keep it for the duration of your browsing session.

CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Site Administration Support Providers

 

II. DOMAIN AND NETWORK SECURITY AND USER AUTHENTICATION
PROCESSING To protect our domains, detect unusual activities, and prevent security threats and protect our site-visitors from unauthorised accesses (such as hackers), we screen all traffic to our sites, and authenticate user log-in information using tokens to verify the details you provide to us and compare it with other available information, such us the credentials you have provided directly to Tikisports or other platforms (such as Instagram or Facebook) or information that is available in the public domain to ensure only “authorised” users have access to our sites.

Use of Cookies/Tags/Pixels: We may collect your personal details for this purpose by using technologies such as cookies, pixels and tags to collect your device information. More information is available in “XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES”.

CATEGORIES OF PERSONAL DETAILS Device information

Identity information

Behavioural and Profile information

Preference information

RETENTION PERIOD Browsing Session

We need your data for as long as you are on the site. We keep it for the duration of your browsing session.

CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Site Administration Support Providers

 

III. GLOBAL CREDENTIAL TO ALL Tikisports PLATFORMS – USER EXPERIENCE
PROCESSING We know you don’t like to remember usernames and passwords, or having to register multiple times.

To enable our users to log on to all platforms, portals, services, communities and apps operated by or on behalf of Tikisports Data Controllers (which includes the Tikisports Running/Tikisports Training app and services) (“Tikisports Platforms”) with one set of log-in credentials (“Tikisports Log-In”), we store your Tikisports Log-In in our global authentication platform. When you use your Tikisports Log-In to enter any Tikisports Platform, we will use a token to verify your identity from our global authentication platform. This also further ensures our network and domain security.

Use of Cookies/Tags/Pixels: We may collect your personal details for this purpose by using technologies such as cookies, pixels and tags to collect your device information. More information is available in “XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES”.

CATEGORIES OF PERSONAL DETAILS Identity information (username, password, email)

Tikisports information (for Tikisports members only)

Preference information

RETENTION PERIOD Your account duration or Inactivity+25 months

To allow you to sign in with your Tikisports Log-In on Tikisports Platforms, we need to maintain your data for as long as you have an account with us, or if you stop using our services without requesting to delete your data, we will keep it for 25 months after your last log in.

CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Site Administration Support Providers

 

IV. SALES OF Tikisports PRODUCTS – ONLINE AND OFF-LINE ORDER
PROCESSING To process your online and/or in-app orders, make sure your payment is received, comply with the requirements under our Terms and Conditions (for selling you the products) including invoice processing, delivery, personalisation services, exchanges and refunds, click and collect. Your order cannot be completed if our payment fraud detection solutions flag your transaction as suspicious and potentially fraudulent. Please note the payment fraud detection system is an automated decision-making process. It is required to allow us to conclude the contract with you. By not providing the required Categories of Personal Details, your order cannot be completed.
CATEGORIES OF PERSONAL DETAILS Identity information

Contact information

Location information

Size information

Purchase information

Correspondence

Device information

Tikisports information (for Tikisports members only)

RETENTION PERIOD Duration of contract and statutory limitation period. We need to keep the information in case of any legal disputes concerning the contract.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Selling Partners (where applicable)

Manufacturing Providers

Delivery Service Providers

Payment Risk Solution Providers

Payment Processing Providers

IT Cloud Solution Providers

 

V. PAYMENT FRAUD DETECTION
PROCESSING We combine the purchase information you provide to us with other information we obtain through our third-party payment risk and fraud prevention service providers to ensure any purchases are legitimate, or you do not purchase our products in violation with our terms and conditions. This means depending on the outcome of the analysis of your information, or if you do not sufficiently provide us with the required Categories of Personal Details, we may reject your order, and decline your payment.
CATEGORIES OF PERSONAL DETAILS Identity information

Contact information

Behavioural and Profile information

Purchase information

Device information

RETENTION PERIOD Duration of contract and statutory limitation period. We need to keep the information in case of any legal disputes concerning the contract.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Payment Risk Solution Providers

Payment Processing Providers

IT Cloud Solution Providers

 

VI. PRODUCT DELIVERY
PROCESSING Once you have successfully placed an order, we use your contact details (home and/or shipping address) and other purchase information to deliver the products you purchased to you. If you do not sufficiently provide us with the required Categories of Personal Details, we may not be able to deliver our products to you.
CATEGORIES OF PERSONAL DETAILS Identity information: Name

Contact information: Shipping Address

RETENTION PERIOD Duration of contract and statutory limitation period. We need to keep the information in case of any legal disputes concerning the contract.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Delivery Service Providers

IT Cloud Solution Providers

 

VII. ELECTRONIC DELIVERY TRACKING
PROCESSING This is a service provided on request of the consumer by our Delivery Partners.

You have the option to track your delivery using services provided directly by our delivery partners; however, we will only be able to share your information with our delivery partners for this purpose with your consent. The service is hosted on the Delivery Partner’s platform. You should read their Privacy Policy for the processing of your Personal Data for this purpose.

CATEGORIES OF PERSONAL DETAILS Identity information

Contact information

Any other information you may directly and voluntarily provide to the Delivery Partner

RETENTION PERIOD As determined by our Delivery Partner.
CATEGORIES OF RECIPIENTS Delivery Service Providers

 

VIII. BUSINESS OPERATIONAL ANALYTICS
PROCESSING We need to know how we do as a business. This is in the interest of our shareholders, our board members, our employees, and our partners. For this purpose, we need to analyse different categories of information to understand how our products are selling in different markets, what are the popular features of our products, what worked and what didn’t in terms of our marketing and advertising campaigns, our product designs and distribution strategy, our website design and overall user experience, so we can establish, implement, and evaluate our business strategy.

This includes analysing data to understand how users browse our site and use the app to improve our user experience design to make sure you will continue to purchase our products and interact with us on our sites and applications.

To minimise the risk to you as an individual, we will only use either the unique consumer identifier or the IP address for this purpose.

You can learn more about how our Data Analytics Solution Providers provide analytics services by using your data here:

Adobe Analytics Data Collection:

https://marketing.adobe.com/resources/help/en_US/reference/c_Privacy_Overview.html

Google Analytics Data Collection:

https://support.google.com/analytics/answer/6318039?hl=en

CATEGORIES OF PERSONAL DETAILS Identity information: Unique Consumer Identifier (only)

Size information

Purchase information

Behavioural and Profile information

Community information

Activity information

Device information

Correspondence

Tikisports information (for Tikisports members only)

RETENTION PERIOD When using analytics services provided by the vendors identified above, we are required to retain data for the period specified by these vendors. You can find the retention period indicated by the vendors here:

Adobe Analytics: 36 months

(https://marketing.adobe.com/resources/help/en_US/reference/data-retention.html )

Google Analytics: 38 months

(https://support.google.com/analytics/answer/7667196?hl=en)

We need the information for this duration to produce accurate analysis of our business operations.

CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Prospective Buyers and Investors

Business Consulting Service Providers

Data Analytics Solution Providers

IT Cloud Solution Providers

 

IX. CUSTOMER SERVICE
PROCESSING We collect your Personal Data to tell you when the product you like is available upon your request and respond to your questions and concerns through various communications channels we make available to you.
CATEGORIES OF PERSONAL DETAILS Identity information

Contact information

Location information

Size information

Purchase information

Correspondence

Tikisports information (for Tikisports members only)

RETENTION PERIOD Statutory limitation period. We need to keep the information in case of any legal disputes.
CATEGORIES OF RECIPIENTS Customer Service Provider

Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Selling Partners (where applicable)

Delivery Service Providers

Payment Risk Solution Providers

Payment Processing Providers

IT Cloud Solution Providers

 

X. PERSONALISED MARKETING MESSAGES VIA EMAIL (Newsletter Sign-Up)
PROCESSING We send you marketing messages that we think you would be interested in (“personalised”) to the email address you provide to us because you signed up to our email newsletters or otherwise consented to receiving marketing messages. To send you “personalised” messages, observe your online (and sometimes, where applicable, offline) behaviour, and analyse your behaviour using analytics to best estimate what product lines you might be interested in, and you can benefit from. This requires us to collect various categories of Personal Data from you. We use different analytics tools to understand what your behaviour means in terms of your like and dislike of our various product lines, and to understand the impact (success rates) of the messages delivered to you.

Use of Cookies/Tags/Pixels: We may collect your personal details for this purpose by using technologies such as cookies, pixels and tags to collect your device information. More information is available in “XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES”.

CATEGORIES OF PERSONAL DETAILS Identity information

Contact information (if available to Tikisports)

Location information

Size information (if available to Tikisports)

Purchase information (if available to Tikisports)

Behavioural and Profile information (if available to Tikisports)

Community information (if available to Tikisports)

Social Media information (if available to Tikisports)

Activity information (if available to Tikisports)

Device information

Preference information (if available to Tikisports)

RETENTION PERIOD We retain it for as long as you do not withdraw your consent sending you emails or object to us processing your Personal Data for marketing purposes.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Email Marketing Support Providers

IT Cloud Solution Providers

 

XI. PERSONALISED MARKETING MESSAGES VIA EMAIL (via existing contract)
PROCESSING We send you marketing messages that we think you would be interested in (“personalised”) to the email address you provide to us during a purchasing contract. To send you “personalised” messages, observe your online (and sometimes, where applicable, offline) behaviour, and analyse your behaviour using analytics to best estimate what product lines you might be interested in, and you can benefit from. This requires us to collect various categories of Personal Data from you. We use different analytics tools to understand what your behaviour means in terms of your like and dislike of our various product lines, and to understand the impact (success rates) of the messages delivered to you.

Use of Cookies/Tags/Pixels: We may collect your personal details for this purpose by using technologies such as cookies, pixels and tags to collect your device information. More information is available in “XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES”.

CATEGORIES OF PERSONAL DETAILS Identity information

Contact information (if available to Tikisports)

Location information

Size information (if available to Tikisports)

Purchase information (if available to Tikisports)

Behavioural and Profile information (if available to Tikisports)

Community information (if available to Tikisports)

Social Media information (if available to Tikisports)

Activity information (if available to Tikisports)

Device information

Preference information (if available to Tikisports)

Tikisports information (for Tikisports members only)

RETENTION PERIOD We retain it for as long as you do not object to us processing your Personal Data for marketing purposes, including sending of marketing messages.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Email Marketing Support Providers

IT Cloud Solution Providers

XII. TARGETED MESSAGES ON 3RD-PARTY ADVERTISING PLATFORMS
PROCESSING We use third-party advertising platforms, such as Facebook, Google, YouTube, Instagram, etc. to send you messages that are targeted at you, based on your behaviour and browsing pattern, at specific times and locations of these platforms to increase the efficiency of our advertising campaigns. We use third-party solutions such as Google Audience and Facebook Custom Audience to help us do a better job at targeting our campaigns and messages for our consumers. Your Personal Data is shared with the third-party advertising platforms, and they will attempt to match your profile in their database to determine the optimal time and place (the page you are browsing) to show you an advertisement from Tikisports. We also need to analyse necessary information to understand the impact of our campaigns. If you don’t accept that we track you for this purpose, you will still see Tikisports advertisements on other platforms at random.

You can learn more about how our Advertising Partners help us achieve this purpose by visiting their sites:

Google Personalised

Advertising: https://support.google.com/adspolicy/answer/143465?hl=en

Google Advertising Policies: https://support.google.com/adspolicy/answer/6020956

Facebook Lookalike

Audiences: https://www.facebook.com/business/help/164749007013531

Facebook Custom Audience

Terms: https://www.facebook.com/legal/terms/customaudience

Use of Cookies/Tags/Pixels: We may collect your personal details for this purpose by using technologies such as cookies, pixels and tags to collect your device information. More information is available in “XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES”.

CATEGORIES OF PERSONAL DETAILS Identity information

Contact information (if available to Tikisports)

Location information

Size information (if available to Tikisports)

Purchase information (if available to Tikisports)

Behavioural and Profile information (if available to Tikisports)

Community information (if available to Tikisports)

Social Media information (if available to Tikisports)

Activity information (if available to Tikisports)

Device information

Preference information (if available to Tikisports)

Tikisports information (for Tikisports members only)

RETENTION PERIOD We retain it for as long as you do not withdraw your consent.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Advertising Agency Partners

Social Media Platforms

Targeted Marketing Service Providers

IT Cloud Solution Providers

XIII. Tikisports MEMBERSHIP ADMINISTRATION – WHERE APPLICABLE
This section applies when you create and register a membership account and become an Tikisports member.

Tikisports collects and uses your Tikisports membership Personal Data for the purposes of:

1. Compliance with Membership Terms and Conditions; and

2. Profiling for Personalised Content, Experience, Business & Marketing Analytics and Targeted Marketing Messages

1. Compliance with Membership Terms and Conditions
PROCESSING When you register and create a membership account, we collect and use your Personal Data to administer your account and comply with the Tikisports Terms and Conditions.

This includes the following:

a. collecting, storing, and processing the Personal Data you provided in the registration form to create a membership profile and account for you;

b. assigning a membership ID to your profile and account and using the membership ID along with other Identity Information you provided to identify you;

c. enabling your membership account details to be used as your Tikisports “Global Credential” for accessing all Tikisports brand domains and apps worldwide;

d. displaying your current membership status, including your profile information, level, points, and other relevant information in all Tikisports brand domains and apps worldwide;

e. sending you membership administration messages via email including messages about your account status (level up and/or down), management (rewards unlocked for you and how to retrieve them) and maintenance requests (for example, password reset);

f. sending you membership administration messages via push notification in Tikisports app about your account status (level up and/or down), and management (rewards unlocked for you) and maintenance requests (for example, password reset) – you can switch off push notifications at any time using “Settings” in your mobile devices. However, if you switch off push notifications, we may need to contact you via emails for important messages relating to your membership;

g. verifying and using your profile and account information for the purpose of participating in member-exclusive challenges and/or promotions – this will also include sharing your contact details with partners who support us with administering the promotions especially in the case where you have won a prize;

h. calculating your club points to provide you with rewards – this will include sharing your data with partners who support us with administering the reward, where the reward may be provided via a partner or exclusively by the partner;

i. updating your point status once you have used points to redeem awards;

j. keeping track of your redemption activity and history;

k. providing you with access to special offers and promotions;

l. sending you invitations to exclusive events;

m. allowing you access to limited edition products;

o. providing you with access to Tikisports Running and Tikisports Training premium features offered as a reward of membership in accordance with membership Terms and Conditions;

q. storing your shipping address and payment details to shorten check-out time online and in the app;

r. storing your complete order history so that you can access it at any time;

s. allowing you to track your order delivery from your account;

t. accessing your membership profile and providing you with services and support – including updating your account information following your instructions, providing you with support and answering your queries about your account, your purchases, technical support for using our apps, supporting you with your privacy queries – when you contact Tikisports through various communication channels using your membership ID and profile; and

u. storing all Personal Data we collect from you directly or indirectly that have been identified via your membership ID or email with your membership profile, including details you may have shared at an Tikisports brand retail store and/or outlet and participating Tikisports franchised stores for the purposes of calculating points and levels to enable all the points listed above.

CATEGORIES OF PERSONAL DETAILS Membership Administration Information

Identity Information

Contact Information

Browsing Information

Mobile Device Information

Correspondence

Image and Recordings (when available to Tikisports)

Personal Opinion (when available to Tikisports)

Measurements (when available to Tikisports)

Payment, Purchase and Transaction Information (when available to Tikisports)

Social Media Interaction and Activity (when available to Tikisports)

Fitness Activity Information (when available to Tikisports)

Behavioural and Preference Information (when available to Tikisports)

RETENTION PERIOD Duration of contract and statutory limitation period. We need to keep the information in case of any legal disputes concerning the contract.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Prospective Buyers and Investors

Business Consulting Service Providers

Data Analytics Solution Providers

Tikisports Partners

2. Profiling for Personalised Content, Experience, Business & Marketing Analytics and Targeted Marketing Messages
PROCESSING We use your Personal Data to create personalised content for you and to make sure we interact with you in a manner that you are more likely to keep and maintain your membership, respond to our targeted marketing messages, and to continue to purchase Tikisports products and use Tikisports platforms.

This includes the following:

a. sending you personalised email messages about how to gain Club points or retain your level including promotional messages about Tikisports products, services and lifestyle recommendations – you can unsubscribe from this message at any time by using the “Unsubscribe” function in the message;

b. sending you push notifications via Tikisports app about how to gain Club points or retain your level including promotional messages about Tikisports products, services, and fitness and lifestyle recommendations – you can switch off push notifications at any time using “Settings” in your mobile devices. However, you may still receive email messages from which you can unsubscribe directly in the email messages;

c. tracking and monitoring your online browsing behaviour by using certain tracking technologies (e.g. Cookies, Pixels, Tags) on the website and in our apps;

d. storing all Personal Data we collect from you directly or indirectly that have been identified via your membership ID or email with your membership profile, including details you may have shared at an Tikisports brand retail store and/or outlet and participating Tikisports franchised stores for the purposes of using them to enrich your membership profile as detailed below; and

e. analysing and assessing all Personal Data we collect from you directly or indirectly that have been identified via your membership ID or email with your membership profile, including details you may have shared at an Tikisports brand retail store and outlet and participating Tikisports franchised stores. More specifically, this includes using your Personal Data in the following ways:

• PROFILING (AUDIENCE MANAGEMENT)

We create a profile about you by consolidating all the information you provided to us directly or indirectly. This allows us to establish a personalised interaction with you that is based on our past interaction, and other information we can use to infer your likes and dislikes. We use audience management technologies to ensure the right messages and information reach you at the right moment through the right channel. This includes sending you marketing messages of deals and products or addressing you across digital media through ads on Tikisports brand platforms.

• MARKETING ANALYTICS

We use your data for different analytical purposes to better understand: a) how you browse and use our platforms; b) which products you are interested in; c) which features of our products and platforms you like; d) the quality of our services including customer service, marketing and advertising campaigns addressed to you, and your reaction to these services; e) our product and website design; and f) whether overall user experience worked for you or not. We use this analysis to improve the relevance of our marketing communication to you and the quality of our personalisation experience across our channels and platforms.

• DATA ENRICHMENT

We create a single, unified consumer profile of you by matching all Personal Data from which you can be identified. This includes Personal Data we collected directly or indirectly from you across digital media or offline, the feedback you provide to us, your interaction and communication with us through our various platforms and communication channels.

• IMPROVING DATA MODELS

We use data science and your profile and Personal Data to create data models that can help us improve the logic in our analytics activities that give us more insight about your comments and feedback, your interactions, preference and needs in our products and services. We will compare the data model we created using your profile with other similar consumer profiles and categories to further predict and analyse your preference.

CATEGORIES OF PERSONAL DETAILS Membership Administration Information

Identity Information

Contact Information

Browsing Information

Mobile Device Information

Correspondence

Image and Recordings (when available to Tikisports)

Personal Opinion (when available to Tikisports)

Measurements (when available to Tikisports)

Payment, Purchase and Transaction Information (when available to Tikisports)

Social Media Interaction and Activity (when available to Tikisports)

Fitness Activity Information (when available to Tikisports)

Behavioural and Preference Information (when available to Tikisports)

RETENTION PERIOD Duration of membership and for as long as you do not object to our legitimate interest by deleting your Personal Data
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Prospective Buyers and Investors

Business Consulting Service Providers

Data Analytics Solution Providers

Email Marketing Support Providers

Tikisports Partners

XIV. PRIVATE EVENT REGISTRATION
PROCESSING When you sign up for an event we organise that have limited spots, we use the Personal Data you provide to reserve a spot for you, and without your Personal Data a spot cannot be reserved for you. Your Personal Data will be used according to the Terms and Conditions associated with the event.
CATEGORIES OF PERSONAL DETAILS Identity information

Contact information

Location information

Activity information: any information we may collect from you on the day of the event.

Tikisports information (for Tikisports members only)

RETENTION PERIOD Duration of the event and statutory limitation period in case of any disputes.
CATEGORIES OF RECIPIENTS Tikisports Controller organizing the event.

Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Event Partners (where applicable)

IT Cloud Solution Providers (where applicable)

XV. OPEN EVENT REGISTRATION
PROCESSING We often also organize events that are open to everyone. We use the Personal Data you provide to keep you informed of the events you are interested in.
CATEGORIES OF PERSONAL DETAILS Identity information

Contact information

Location information

Activity information: any information we may collect from you on the day of the event.

Tikisports information (for Tikisports members only)

RETENTION PERIOD For the duration of the event + 36 months if the data from a particular event is used for BUSINESS OPERATIONAL ANALYTICS purpose.
CATEGORIES OF RECIPIENTS Tikisports Controller organizing the event.

Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Event Partners (where applicable)

IT Cloud Solution Providers (where applicable)

XVI. PRODUCT RESEARCH AND DEVELOPMENT
PROCESSING We conduct analysis to research improve our products and services. This includes asking you questions in surveys, asking you for feedback, asking you to test our products and provide us with a review, asking other service providers to conduct market and product research for us, try new technologies in our product that might collect Personal Data to stay ahead of the competition.
CATEGORIES OF PERSONAL DETAILS Identity information (only if required by the project)

Contact information (only if required by the project)

Location information (only if required by the project)

Size information

Purchase information (only if required by the project)

Behavioural and Profile information (only if required by the project)

Community information: this is the response you provided whichever format agreed at the time of the project.

Social Media information (only if required by the project)

Activity information (only if required by the project)

Device information (only if required by the project)

Correspondence (only if required by the project)

Preference information

Tikisports information (for Tikisports members only)

Health information: if a project requires you to also provide health information, we will explicitly ask for your consent.

RETENTION PERIOD The duration of the project and statutory retention period stated to protect our IP rights.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Prospective Buyers and Investors

Business Consulting Service Providers

Data Analytics Solution Providers

Manufacturing Providers

IT Cloud Solution Providers

XVII. LEGAL OBLIGATION – COOPERATION WITH LAW ENFORCEMENT AND REGULATORY AUTHORITIES (INCLUDING COURTS)
PROCESSING When we are legally required to provide your Personal Data for national and public security reasons, crime prevention, investigation and prosecution, anti-money laundering, judicial proceedings, protection of other individuals’ rights and freedoms, and enforcement of civil claims, we will provide information as requested by the authorities or parties once we are satisfied that the request is mandated by law. We may not be able to notify you if it is against the law to do so.

If you do not provide us with any of the required Categories of Personal Details, it may result in us and/or you being deemed to violate or be in non-compliance with the applicable law or order of the competent authority.

CATEGORIES OF PERSONAL DETAILS All Categories of Personal Data as requested by the enforcement authority.
RETENTION PERIOD For as long as required by law.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Local and national government authorities, including tax authorities

Local and national law enforcement agencies

Local and national judiciary

 

XVIII. COLLECTING YOUR DEVICE INFORMATION ON OUR WEBSITE USING COOKIES, PIXELS, TAGS, AND SIMILAR TECHNOLOGIES (“COOKIES NOTICE”)
When you visit the Tikisports site, we store data collectors such as cookies, tags, pixels, tag containers, beacons, among others, in your browser to obtain certain information about your current browsing session. These technologies are often referred to as “Cookies” collectively by other websites. Cookies also enable our website to remember your actions and preferences (such as login, language, font size and other display preferences) over a period, so you don’t have to keep re-entering them whenever you come back to the site or browse from one page to another. We use Cookies for different purposes, which also mean they have different legal bases. Please review the information below to understand how we use different types of Cookies to fulfil different purposes.
PROCESSING “REQUIRED” – site functionality and business operation.

We use “Required Cookies” to operate our site. This includes storing a unique identifier to manage and identify you as a unique visitor to our site, to provide a consistent and accurate service to you. This includes making sure that we remember the products you have placed in your cart, or your language preferences. These Cookies are stored for the duration of your browsing session. Without these Cookies, you will not be able to view our site properly.

PROCESSING “FUNCTIONAL” – website improvement and performance

We use “Functional Cookies” to continuously improve our website performance. This includes using the data we collected from you to do the following:

Web analytics —Based on your browsing behaviour, we will analyse the data to improve the functionality and design of our site.

Ad response rates— Based on how you come to our site, we will measure our ad response rates by analysing our ad click-through rates to improve the effectiveness of advertising purchased on a site external to ours.

Affiliate tracking— We need to let our affiliate marketing partners, or service providers have certain information if you came to our site, and purchased products, through a visit to theirs. This is required as we may need to provide them a fee for such services. For this purpose, we will share information about your visit, including the products you have purchased.

Error management— We measure errors presented on a website, to make sure we fix bugs or any issues promptly.

Testing designs— We need to use A/B testing or multivariate testing, to ensure a consistent look and feel is maintained for the user of the site in the current and subsequent sessions.

PROCESSING “MARKETING”

We use “Marketing Cookies” provided by our advertising partners to make sure our advertising messages are shown to you at the right time and the right place. These Cookies are persistent but time-limited cookies. These Cookies contain a unique key to distinguish individual users’ browsing habits. We also use these Cookies to limit the number of times a user sees a particular ad on a website and to measure the effectiveness of a particular campaign. The identifier stored by these Cookies are provided by our partners. We cannot use the same identifier in our own systems. We also use these cookies to serve ads that are relevant to your immediate geo-location, for example to provide you with the nearest store where the product you are browsing may be available.

CATEGORIES OF PERSONAL DETAILS Device information

Location information

Behavioural and Profile information: this is collected through observing your browsing behaviour

Preference information (if available to Tikisports)

RETENTION PERIOD The cookies, pixels, tags, and other similar technologies used to collect your device information and browsing behaviour information are stored in your browser for the session or for as long as you do not clear your browser cookie setting.

The data we obtained through the cookies related to other purposes will be stored for the duration of that purpose.

CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Site Administration Support Providers

Business Consulting Service Providers

Data Analytics Solution Providers

Advertising Agency Partners

Social Media Platforms

Targeted Marketing Service Providers

You can change your browser settings to delete or prevent certain cookies from being stored on your computer or mobile device without your explicit consent. The ‘help’ section in your browser should provide information on how to manage your cookie settings.

Find out how this works for your browser here:

Internet Explorer: https://support.microsoft.com/help/17442/windows-internet-explorer-delete-manage-cookies

Mozilla Firefox: http://support.mozilla.com/en-US/kb/Cookies

Google Chrome: http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95647

Safari: http://support.apple.com/kb/PH5042

Opera: http://www.opera.com/browser/tutorials/security/privacy/

Adobe (flash cookies): http://www.adobe.com/privacy/policies/flash-player.html

Google Chrome

App: https://support.google.com/accounts/answer/61416?co=GENIE.Platform%3DAndroid&hl=en

 

XIX. USER-GENERATED CONTENT (UGC) ACQUISITION FROM SOCIAL MEDIA
PROCESSING We invite you to provide your images to us via social media platforms by following specific instructions such as “#yesTikisports”. We will be using the images you provide for our campaign communications. We will obtain rights to your image through a licence agreement in the form of our terms and conditions. By submitting your images via social media platforms to us, you will agree for us to use your images as described in the licence agreement.
CATEGORIES OF PERSONAL DETAILS Identity information: your social media handler

Community information: images, videos, comments, sound recordings and other files provided through the social media platform promoting Tikisports

Social Media information

RETENTION PERIOD Duration of licence agreement and statutory limitation period in case of any disputes.
RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

Event Partners (where applicable)

UGC Support Partners

Advertising Agency Partners

Social Media Platforms

IT Cloud Solution Providers (where applicable)

 

XX. PUSH NOTIFICATIONS (IN-APP COMMUNICATION)
PROCESSING When you use the Tikisports app, we use push notifications in this app to communicate with you concerning the purposes stated in this Notice. This includes information that relates to purposes based on the Performance of Contract (such as your purchase). You can switch off push notifications at any time using “Settings” in your mobile devices. However, if you switch off push notifications, we may need to contact you via emails for important messages relating to your purchase.
CATEGORIES OF PERSONAL DETAILS Device information
RETENTION PERIOD For as long as you use the app and not switched Push Notification off.
CATEGORIES OF RECIPIENTS Tikisports Data Controllers

WeSUP (Thailand) Co., Ltd.

 

6. What does Tikisports do when we transfer your Personal Data outside of Thailand?

Depending on the Personal Data processing activity, your Personal Data is shared with different “Categories of Recipients”. The recipients could be located in other countries outside Thailand which may have different Personal Data Protection standards to those prescribed by the supervisory authority in Thailand. Nevertheless, we have implemented necessary measures to ensure that the recipients will implement adequate Personal Data protection standards and/or selecting vendors that certify and comply with the requirements and obligations prescribed by the PDPA.

7. How do we secure your Personal Data?

We implement appropriate technical and organisational measures to address the risks corresponding to our use of your Personal Data, including loss, alteration, or unauthorised or unlawful access, use, or disclosure to your Personal Data, and empowering you to exercise your rights. We require our service providers to do the same through contractual agreements. However, you should be aware that any transmission of your Personal Data through the internet is at your own risk. We can only protect your Personal Data when we have it.

8. What are your rights and how can you exercise them?

Under the PDPA, you have the rights listed and explained below. We also provide you with instructions on how to exercise each right. We need to confirm your identity before we can handle your requests. When we refuse your request for legal reasons, we will tell you why.

For all enquiries concerning your privacy and personal data, please contact us at usa@star-board.com 

Please consult your local supervisory authority about your rights and to understand what these rights mean.

YOUR RIGHT HOW TO EXERCISE YOUR RIGHT
Get a copy of your Personal Data

You have the right to obtain a copy of your Personal Data, provided that it does not have a negative effect which may cause damages to the rights and freedom of other people, or it is not otherwise prohibited by law or court order.

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Subject: A Copy of My Personal Data.

Access to information about your Personal Data

You have the right to know whether or not we use your Personal Data, as well as the following information:

a) why we have your Personal Data;

b) what categories of data we have;

c) what we do with your Personal Data;

d) who has access to your Personal Data (and where they are); e) where your Personal Data might be transferred to;

f) how long we are keeping your Personal Data;

g) if you didn’t provide your Personal Data directly to us, how did we get it; and

h) your rights under applicable laws and the possibility to restrict processing.

Please review the Tikisports Privacy Policy.

If you have any questions about the Privacy Policy, please contact the Tikisports Privacy Team.

Request the disclosure of how your Personal Data has been acquired

You have the right to request us to disclosure on the acquisition of your Personal Data which you did not consent to.

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Make sure your Personal Data are correct

You have the right to make sure we are using the accurate, complete and up-to-date details about you.

Log in to your account and make the corrections yourself; or

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Delete, destruct or de-identify your Personal Data

You have the right to ask us to delete, destroy or de-identify your Personal Data if:

a) we no longer need it for a specific purpose, for example, a contract or a legal requirement; or

b) you withdraw the consent you provided if we asked for your consent when we collected your Personal Data;

c) if you object to our use of your Personal Data; or

d) where your Personal Data was unlawfully collected, used or disclosed.

Log in to your account and make the corrections yourself; or

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Restrict how we use your Personal Data

You have the right to stop us from doing certain things to your Personal Data under certain circumstances, including, without limitation, when:

a) your request to have your Personal Data corrected, completed or updated is under examination process;

b) you don’t want us to delete your Personal Data, but you also don’t think we are complying with the law; or

c) your Personal Data is no longer necessary for our purposes, but you wish to have them retained in order to establish, comply, exercise or defend a legal claim.

When you successfully restrict how we use your Personal Data, we will only use your Personal Data with your consent, or unless it is required by law.

Log in to your account and make the corrections yourself; or

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Subject: Privacy – Restrict Processing

Obtain a portable file so you can share it with another data controller

You have the right to obtain a portable file that contains the Personal Data you provided to us where the legal basis is either consent or the performance of contract. The file will provide you with the Personal Data you actively and knowingly provided to us, including data passively obtained by us when you use our service or products, or you may request Tikisports to share such file to another data controller if it can be done through automated means.

Please log-in to your account, go to “Personal Information” and click on “Your Personal Data”. You will receive an encrypted .json file to the designated email address.
Withdraw your consent

When we use your Personal Data based on your consent, you have the right to change your mind and withdraw your consent at any time.

Note that by withdrawing consent, you may not be able to fully enjoy our services, or to use certain functions of our platforms, portals or applications.

Your withdrawal of consent will not affect the lawfulness of our processing based on your consent prior to such withdrawal.

Unsubscribe from our Newsletters:

Click ‘Unsubscribe’ at the bottom of the newsletter or marketing email that you want to unsubscribe from; or update your communication preferences in your account if you have one.

If there are any technical issues:

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Subject: Unsubscribe Me from Emails

Withdrawing other consent:

Contact us for support.

Subject: Privacy – Withdraw My Consent

Object when we process your Personal Data based on the basis of our “Legitimate Interest”

When we process your Personal Data based on “Legitimate Interest”, you may have the right to disagree and stop us from processing your Personal Data for this purpose. We may have compelling reasons, though, to continue processing your Personal Data even in the light of your objection. In such cases we will provide you with our rationale. We will respect and implement your objection in any case where it is related to direct marketing purposes.

If you are objecting to email marketing:

Unsubscribe from our Newsletters:

Click ‘Unsubscribe’ at the bottom of the newsletter or marketing email that you want to unsubscribe from; or update your communication preferences in your account.

If there are any technical issues:

Contact Customer Service for support.

Reason: Privacy and Data Handling.

Subject: Unsubscribe Me from Emails

For all other objections:

Contact Customer Service for support.

Subject: Privacy – Object to Legitimate Interest

File a complaint with your local data protection supervisory authority

If you are not happy with how we have handled your Personal Data, or how we have responded to your rights provided here, you have the right to make a complaint against us with your local data protection supervisory authority.

Contact a data protection supervisory authority

 

9. Questions, Complaints, and Support – who and how you can get in touch with them?

Tikisports Customer Service
ASK CUSTOMER SERVICE: 

wararat@star-board.com

Tikisports Privacy Team and the Data Protection Officer
usa@star-board.com
Data Protection Supervisory Authorities
The Office of Personal Data Protection Commission – Thailand

 

10. Updates and Notification of Updates

We review and update the Privacy Policy periodically to reflect any changes resulting from our day-to-day business operations. You can always check the date of the Privacy Policy to find out when we last made any changes. We will notify you in advance when we make significant changes that you must be aware of and in particular, if changes would affect the purposes of which your Personal Data has originally been collected and, where applicable, we will obtain your consent prior to such changes being effective.

11. Tikisports Data Recipients

We may disclose your personal data to the following parties (“Data recipients”):

We may disclose your personal data to the following parties (“Data recipients”):

agents, sub-contractors, vendors or third party service providers, such as courier services, telecommunications, technical services, debt recovery, market research and data analytics services;

any other party to whom you authorise us to disclose your personal data to;

our marketing and business partners in connection with marketing promotions, products and services;

our corporate clients;

amongst the Tikisports corporate group and its related corporations or affiliates;

our professional advisers, such as our lawyers and accountants;

banks, payment processing service providers, financial institutions and their respective service providers;

our successor-in-title, prospective seller or buyer of any part or the whole of our business, in connection with a merger, acquisition or sale of any part or the whole of the Tikisports business; and

social media sites such as Facebook, Twitter or Google.

 

In case you require information with whom your data is being shared, you may reach the local DPO as set out at Section 9 above.

Where your Personal Data may be used by non-Tikisports Data Users via Tikisports Platforms, applications or elsewhere for their own purposes, please consult the privacy policy of the non-Tikisports Data Users for more information about how they handle your Personal Data.