Petee legal
Privacy Notice
How Petee collects, uses, discloses, transfers, retains, and protects personal data, and how people can exercise their rights.
1. Controller and scope
This Privacy Notice applies to the Petee mobile application, website, support channels, and related Member and Trainer services. The data controller is Peteefit, based in Bangkok, Thailand. Petee can be contacted through in-app Support.
This Notice includes the Trainer identity-document process, including the masked-image requirements, restricted review access, retention, and deletion rules described below.
2. Personal data Petee collects
The data Petee processes depends on whether you are a Member, Trainer, applicant, visitor, or support contact and which features you choose to use.
- Identity, contact, and account data: name, email address, telephone number, LINE ID, avatar, authentication identifier, role, emergency-contact details, sign-in and security records, and records of accepted terms or consents.
- Fitness and health data: goals, specialties, training preferences and mode, height, weight, target measurements, injuries, relevant limitations, and doctor-clearance responses. Health data is sensitive personal data.
- Location data: a private precise saved Home, a separate rough Gym search point and travel range, Trainer travel bases and service areas, public venues, and locations selected for sessions.
- Trainer and application data: display name, biography, gender, experience, qualifications, certificates and supporting evidence, social links, profile photos or videos, availability, service areas, packages, and review status. For identity review, Petee also collects the applicant's private legal name, document type, and one masked front image of a Thai national ID card or Thai driving licence. Petee does not treat a review as a criminal-record, medical-license, or insurance check unless expressly stated.
- Petee visually reviews the identity image and does not extract or separately store the document number, address, date of birth, OCR text, face template, or biometric identifier. The applicant must cover the ID or licence number, address, religion, signature, and laser, barcode, or QR code before uploading.
- Activity, communication, and content data: matching inputs and results, messages and read status, blocks, bookings, attendance and check-ins, session notes, cancellations, disputes, support conversations, reports, ratings, comments, and media you choose to upload.
- Commercial and payment-related data: package and session details, prices, payment status, provider references, refunds, Trainer earnings, payout records and private transfer proof, and limited payment-method details returned by a payment provider. Petee does not intend to store full card numbers or card security codes.
- Device, permission, security, and technical data: app and operating-system version, device or push-notification token, selected permissions, timestamps, service and audit logs, network and security events, and bounded error or abuse-prevention information.
- Optional product analytics described in section 8.
3. Where personal data comes from
Clerk processes email/password sign-in, email verification, recovery and session security. If you choose Apple or Google, that provider supplies the identity information you authorize. Petee uses the verified identity to bind your account. Passwords, verification codes, one-time Apple authorization codes and Apple provider tokens are not stored in Petee databases or logs. Session credentials are protected by the authentication provider and the device secure storage.
Petee receives data directly from you; automatically from the app, device, and Platform when you use a feature; from Members, Trainers, venues, and support staff involved in a booking or report; and from service providers such as authentication and payment providers. Petee may also verify Trainer information against issuing bodies or lawful public sources where appropriate.
If you provide data about another person, such as an emergency contact, you must be authorized to do so and should tell that person how Petee will use the data.
4. Required and optional data
Before final submission of member or trainer setup, Petee retains only the verified account and its legal acceptance. Unfinished form answers remain in device memory and are cleared by a full app restart, sign-out, account change or explicit discard. Selected photos and certificates are uploaded only when you submit; uncommitted setup upload reservations expire after 15 minutes and their objects are reclaimed by the existing cleanup process. Abandoning setup does not delete your account; you may explicitly request account deletion.
Account, authentication, transaction, and legally required records are necessary for the features to which they relate. Without them, Petee may be unable to create or secure an account, verify a Trainer, complete a booking or payment, provide payout, investigate a complaint, or comply with law.
Health information, device location, optional profile fields, media, and product analytics are optional unless Petee clearly identifies a particular item as necessary for a requested feature. Declining health information may reduce the relevance or safety context of matching; declining device location still allows manual location entry where that option is available; declining analytics does not affect access to Petee. Trainer identity review is currently optional and is not required to submit or activate a Trainer application. If Petee later makes identity review mandatory, Petee will update the application flow and this Notice before enforcement.
5. Purposes and lawful bases
Petee processes personal data only where it has an appropriate lawful basis under applicable law.
- Contract and steps requested before a contract: creating and securing accounts, visually reviewing Trainer identity evidence, matching Members and Trainers, displaying published packages, messaging, booking, payments, refunds, attendance, Trainer payouts, and support.
- Legal obligations and legal claims: accounting, tax, consumer protection, payment records, lawful requests, data-protection duties, complaints, disputes, and enforcement of Platform rules.
- Legitimate interests, after balancing them against individual rights: protecting users and the Platform, preventing identity fraud and abuse, retaining reviewed evidence for the stated fraud and dispute period, maintaining service reliability, limited auditing, resolving disputes, and improving non-sensitive service operations.
- Consent: processing sensitive health data, optional product analytics, marketing if introduced, and device permissions where consent is required. You may refuse or withdraw consent without losing unrelated services. Withdrawal does not affect processing already lawfully completed.
- Vital interests or another basis permitted by law may apply in a genuine emergency, but Petee support is not an emergency or medical service.
6. Sensitive health and fitness data
Petee uses health and fitness information only to support requested matching, help a Trainer understand relevant safety context, and operate the selected training service. It is not medical diagnosis or treatment and is not used for third-party advertising, unrelated eligibility decisions, or sale.
Health questions appear directly with a short inline notice and a Privacy link to the detailed notice and policy. During first-run setup, answers and consent choices remain an unsent, temporary on-device draft until final submission. Agree & continue, or Agree & save in an editor, records an explicit choice to save and use health details for matching and training; first-run setup sends that choice with the final submission, while completed-profile editors save immediately. It leaves the separate trainer-sharing choice unchanged; sharing is off for new members. Skip for now discards the current unsaved injury answer without deleting saved details or withdrawing consent. Weight Loss requires measurements, so members who decline choose another goal. General acceptance of the Terms is not health-data consent.
When sharing is enabled, selected goals and focus areas, volunteered injuries, relevant height and current/target weight, and optional self-reported doctor-clearance answers are available only to trainers with a current relationship and a confirmed booking in that relationship episode. This includes eligible future, replacement, and cover trainers. Blocked and past relationships cannot access them. Doctor clearance is reported by the member; Petee does not collect a certificate or verify clearance.
Members can turn sharing off in Profile → Privacy while keeping their details private for matching. Manage saved health details allows deletion and withdrawal of storage consent; this deletes injuries, doctor answers and measurements and removes Weight Loss, without cancelling bookings. Sharing of remaining goals follows the separate sharing choice. Consent lasts until withdrawal or a material change requiring a new choice; health details are retained until deletion, withdrawal or account erasure, subject to the retention exceptions below. Withdrawal stops future access but cannot recall information a trainer previously viewed.
7. Location, media, notifications, and device permissions
Petee requests foreground location only when you use a location feature. A precise saved Home is private and used for serviceability; Gym discovery uses a separate rough search point. Petee does not use background location and does not place a private Home in public discovery, product analytics, or marketing systems.
You can deny or revoke device permissions in operating-system settings and can enter a location manually where offered. If you select or capture media, enable notifications, or use device authentication, the relevant operating-system and service providers also process the data. Petee receives the selected media and notification token but does not receive biometric templates used by the device.
8. Optional product analytics
If you expressly opt in, the native app sends a limited set of manually defined workflow milestones to PostHog to measure completion, abandonment, time to completion, blockers, and repeat booking in onboarding and booking flows. You can withdraw through the in-app analytics setting at any time without affecting Petee services.
This stream uses a random installation-scoped identifier, event time, platform, app version and build, analytics environment, and bounded milestone or outcome values. Petee does not attach names, contact details, authentication or account identifiers, booking or payment identifiers, health data, locations, payment amounts, free text, routes, provider URLs, or raw errors. The identifier resets when the signed-in account changes.
Petee disables automatic screen and touch capture, app-lifecycle capture, session replay, surveys, automatic error capture, feature flags, GeoIP enrichment, and identified person profiles for this stream. Analytics is not used for advertising, automated eligibility, Trainer ranking, pricing, or health profiling.
9. Disclosure and public information
Petee discloses only data reasonably needed for the relevant purpose: between a Member and Trainer for matching, communication, booking, location coordination, safety context, and service delivery; to authorized Petee personnel for operations, review, safety, support, and legal duties; and to the providers in section 10. A Trainer receiving Member data must use it only for the requested service and comply with applicable privacy law. A Trainer may separately control records they lawfully create outside Petee and should provide their own notice where required.
Trainer listing information and other content clearly marked for publication may be visible to Platform users or the public. Private health data, exact Home, private messages, payment details, certification evidence, and support records are not public. A rating or review may be displayed with the account information shown when it is submitted; the final interface must make that visibility clear.
A completed private transfer proof is available only to currently authorized administrators through an audited, short-lived access grant. It is not shown to trainers or members and is never a public profile or message attachment. Proof is immutable after the payout is Paid.
A Trainer applicant's legal name and identity image are never included in public profiles, public APIs, analytics, or cached image delivery. While an application is pending, a currently active platform administrator may request a direct link that expires after five minutes. After a decision, routine administrator access ends; only an account on Petee's platform-owner allowlist may reopen the image for a recorded fraud, dispute, or appeal reason. Each list, image access, exceptional access, and decision is audited.
Petee may disclose data to professional advisers, auditors, insurers, authorities, courts, or transaction counterparties when reasonably necessary and legally permitted, including for a corporate reorganization. Petee does not sell personal data and does not provide it for third-party behavioral advertising.
10. Service providers
Depending on the deployed feature, Petee uses providers for authentication (Clerk), payments and payment networks (including Stripe, banks, and PromptPay participants), application hosting and databases (including Google Cloud and Neon), file and image storage or delivery (including Cloudflare or configured S3-compatible services), push notifications (Expo, Apple Push Notification service, and Firebase Cloud Messaging), maps and geocoding (including Longdo Map and Google Maps), app distribution (Apple and Google), and opt-in product analytics (PostHog). Each receives only the data needed for its role and may process technical data under its own privacy notice.
Petee reviews this list as production services change and updates this Notice when a material recipient is added. Petee requires providers handling personal data on its behalf to follow applicable data-protection and confidentiality obligations.
11. International transfers
Some providers and their subprocessors operate outside Thailand. Petee will transfer personal data only where the destination has adequate protection or Petee uses another mechanism permitted by Thai law, such as appropriate contractual and organizational safeguards or a specific legal exception. You may request information about applicable safeguards through in-app Support.
12. Retention
Account-cleanup requests remain while provider deletion is pending, with only the identifiers and bounded state needed to complete it. After cleanup finishes, a restricted record that prevents old sessions or delayed provider events from restoring the erased account is retained for 90 days. No password, verification code or Apple provider token is kept in this record.
Petee keeps personal data only as long as needed for the stated purpose and then deletes or irreversibly anonymizes it, subject to legal holds and mandatory retention. When a fixed period cannot be stated, Petee uses the shortest period reasonably necessary based on the account or contract lifecycle, applicable limitation periods, fraud and safety needs, and legal obligations.
- Account and profile data: while the account is active and afterward only as long as reasonably needed to close the account, prevent fraud, handle complaints or disputes, and comply with law.
- Bookings, payments, earnings, payouts, invoices, tax, and audit records: for the period required by applicable Thai accounting, tax, consumer, payment, and claims law.
- Required Paid transfer proof is retained for the same lifecycle as its payout record under the existing financial-retention rules. Replaced or cancelled-unpaid proof uploads are deleted after their upload grants expire so an old upload cannot recreate an orphaned object.
- A current approved Trainer identity image and legal name: while the complete Petee account remains active, then for 12 months from the database-recorded account deletion time. Routine access is revoked immediately at deletion. Reopening an account does not cancel the deadline; a new application and image are required.
- An explicit privacy-erasure request uses the same 12-month identity-document period while access remains restricted. Petee shortens the period if applicable law requires earlier deletion.
- An incomplete or pending identity application: 30 days. An ordinarily rejected identity image: 90 days from decision. A superseded approved image: 30 days from replacement.
- An image rejected for unmasked fields or withdrawn before decision is removed from Petee access immediately and queued for provider deletion. An upload that never reaches an application is deleted within 24 hours.
- Other messages, reviews, reports, safety, support, and Trainer-verification records: while needed to deliver the service and afterward only as long as reasonably necessary for complaints, safety, verification, disputes, or legal obligations. Public content may instead be anonymized where lawful and necessary to preserve an accurate marketplace record.
- Push tokens: until sign-out, revocation, invalidation, or account closure makes them unnecessary. Opt-in product analytics: no more than 12 months, and earlier when no longer needed.
- Backups: until overwritten or securely deleted under Petee’s documented backup cycle.
13. Security and incidents
Petee uses proportionate technical and organizational safeguards, including access controls, role separation, transport encryption, secret management, audit records, provider review, and incident procedures. No service can guarantee absolute security. If a personal-data breach triggers a legal notification duty, Petee will notify the competent authority and affected people within the periods and with the information required by law.
14. Your rights and account deletion
Deleting your Petee account closes access and removes or anonymizes account data under the retention rules below. Deletion of the Clerk identity may continue afterward; the app reports this as cleanup pending until confirmed. For linked Apple sign-in, Petee first requests a fresh Apple authorization to revoke its access automatically. When that cannot be completed, you can choose the official manual Apple account settings instructions and explicitly confirm your choice. Manual confirmation is not proof that Apple revocation succeeded, and the app does not describe it as verified. A request may be cancelled before provider cleanup begins; afterward it must resume because an irreversible action may already have occurred.
Subject to applicable conditions and exceptions, you may request access and a copy, correction, portability, objection, restriction, deletion or anonymization, and information about sources or recipients. You may withdraw consent as easily as it was given and complain to Thailand’s Personal Data Protection Committee. Petee may verify identity and will respond within the period required by law; if it refuses a request, it will record and explain the lawful reason.
You may request account deletion through the account-deletion path identified in the app or on Petee's website, or contact in-app Support if you cannot use it. Petee will cancel or resolve outstanding obligations, delete or dissociate account-linked data, and retain only records for which a lawful ground remains. Retained records will be restricted to that ground and deleted or anonymized when it expires.
Account erasure removes current training and health preferences, measurements, safety answers, saved places, preferred-Home links, and member health-storage and trainer-sharing permissions. Necessary package, purchase, session, earning, payout, and Paid-proof records remain anonymized under their financial-retention lifecycle. Unpaid booking targets are released; a later confirmed payment after erasure follows the original-payment refund process and does not recreate service or personal data.
Under the current Trainer identity policy, deleting the complete Petee account or making an explicit erasure request immediately ends routine access but schedules the current approved legal name and identity image for deletion 12 months later. Petee applies an earlier deadline if the law requires it.
Because opt-in product analytics is deliberately not linked to a Petee account, Petee may be unable to find a particular analytics record using information it already holds. Petee will explain that limitation and will not collect extra identity data merely to create the link.
15. Age limit, third-party services, and changes
Petee is designed only for people aged 20 or older and does not support child or guardian-managed accounts. If Petee learns that an ineligible person provided personal data, it will take appropriate steps to close the account and delete or lawfully retain the data.
Third-party sites, venues, payment methods, maps, app stores, and Trainer services may have their own privacy notices. Petee is responsible for its own processing and integrations, not processing independently controlled by those parties.
Petee may update this Notice when its services, providers, or law change. It will publish the new date and version and give prominent advance notice, and obtain fresh consent, where a material change requires it. Earlier versions will be made available where required.
16. Contact, effective date, and version
Questions, consent withdrawals, and rights requests may be submitted through in-app Support. Do not send medical emergencies through this channel.
Controller: Peteefit, based in Bangkok, Thailand. Contact: in-app Support. Website: https://petee.fit. Effective date: 2 October 2026. Version: 2026-10-02.