Version: 1.0
Publication date: 2026-08-11
Effective date: 2026-08-16
The controller of personal data processed in connection with the use of Mealzo is:
Trading name: Mealzo Store
E-mail: hello@mealzo.store
Website: mealzo.store
This entity is referred to below as "Mealzo", "we" or the "Controller".
1. This Privacy Policy explains what personal data Mealzo collects, where it obtains it from, for what purposes it uses it, to whom it may disclose it, how long it retains it, and what rights data subjects have.
2. The Policy covers data processed when using:
3. Mealzo operates as a single brand and a single provider of dietary catering. It is not a marketplace and does not pass Orders to independent restaurants for the purpose of concluding a separate contract with the Customer.
4. This Policy has been prepared with the Personal Data Protection Act B.E. 2562 in force in the Kingdom of Thailand, hereinafter "PDPA", in mind. If mandatory legal provisions afford a person broader protection, those provisions apply.
1. Personal data means information relating to a person that allows them to be identified directly or indirectly.
2. Sensitive data means categories of data subject to special protection, including information about health, allergies, intolerances and restrictions resulting from a health condition.
3. Processing covers any operation performed on data, for example its collection, recording, organisation, use, disclosure, storage or deletion.
4. Customer means a person using Mealzo, creating an Account, placing an Order or receiving Meals.
5. Package means a multi-day set of Mealzo services covering the preparation and delivery of Meals for a specified number of active Delivery Days.
6. Other capitalised terms have the meaning given to them in the current Mealzo Terms and Conditions.
Mealzo may receive data:
1. Directly from you, when you:
2. Automatically from your device and the system, when you use the website or the application. This includes, among other things, the IP address, device data, security logs, language, date and time of activity, session identifiers, and information stored by essential cookies or similar technologies.
3. From sign-in providers, if you choose to sign in with Google or another available service. The scope of data depends on the information presented during sign-in and your settings with the given provider.
4. From the payment operator, once payments go live. Mealzo may receive the payment status, transaction identifier, amount, payment method, payment token and the limited data needed for settlement. Mealzo should not receive or store the full card number or the security code.
5. From a company or institution, if in the future you use a Mealzo programme funded or organised by your employer. This may include your first and last name, work e-mail, employee identifier, department, office location, subsidy rules and participation status.
6. From a person ordering for you, if they designate you as the recipient of a Meal. Such a person should be entitled to share your data with us and should inform you of doing so.
The scope of data depends on the features you use. Mealzo may process the following categories of data.
Mealzo should not store passwords in plain text.
Mealzo uses location primarily to check whether the address is within a served Zone, to plan the delivery and to resolve delivery problems. We do not continuously track the location of the Customer's device, unless a separate feature is expressly described and enabled by the User.
Once payments go live, card or account data will be processed mainly by the chosen payment operator under its own rules.
A preference is not always health information. However, if its content reveals a health condition, an allergy, an intolerance or a medical recommendation, we treat it as sensitive data.
We may process information about:
This data is used only to the extent needed to assess whether we can provide the chosen service, to label Meals, to prepare instructions for the kitchen and packing, to handle incidents, and to contact the Customer.
Providing allergy data does not mean that Mealzo can guarantee the absence of cross-contact. Detailed rules are set out in the Allergen and Food Safety Policy.
1. Data relating to allergies, intolerances and health may be subject to special protection under the PDPA.
2. As a rule, we ask for separate, explicit consent before saving such information in the profile or passing it to the kitchen and packing.
3. Consent for health data is separate from:
4. Consent can be withdrawn. Withdrawing consent does not affect the lawfulness of prior processing, but it may prevent the continued provision of services that require allergies or health conditions to be taken into account.
5. Access to sensitive data should be limited to persons who genuinely need it to perform their duties, for example selected customer service staff, the nutritionist, the kitchen and packing.
6. Mealzo does not use health data for behavioural advertising and does not sell it to other parties.
7. If Mealzo is unable to safely accommodate a reported allergy, it may refuse to accept the relevant modification or Order.
Mealzo processes data only where it has a defined purpose and an appropriate legal basis. Depending on the situation, we rely on one or more of the following bases.
Purpose: registration, login, phone number verification, session maintenance, profile management and providing access to Mealzo features.
Basis: pre-contractual steps and performance of the contract; in specific cases, a legitimate interest related to Account security.
Purpose: Package configuration, price calculation, Order acceptance, schedule creation, Menu assignment, preparation, packing, delivery, handling of changes and contact regarding fulfilment.
Basis: performance of the contract and steps taken at the Customer's request before its conclusion.
Purpose: checking whether Mealzo can deliver the Meals, assigning the kitchen and Zone, planning the route and determining the fee.
Basis: performance of the contract and pre-contractual steps.
Purpose: accepting payment, confirming its status, issuing refunds, settling the Order, and issuing accounting and tax documents.
Basis: performance of the contract and Mealzo's legal obligations.
Purpose: assessing feasibility, limiting risk, providing appropriate instructions to the kitchen and packing, labelling the Meal, and handling incidents.
Basis: explicit consent, unless the law permits another basis in the specific situation.
Purpose: responding to enquiries, resolving problems, handling complaints, refunds, delivery errors and food incidents.
Basis: performance of the contract, legal obligation, and a legitimate interest in ensuring service quality and defending claims.
Purpose: protecting Accounts, infrastructure, payments and data; detecting attempted fraud, unauthorised access, price manipulation or promotion abuse.
Basis: legal obligations and the legitimate interest of Mealzo and its Customers in security.
Purpose: fixing errors, measuring performance, testing features, improving usability, analysing feature usage and planning operational capacity.
Basis: legitimate interest, provided it is not overridden by the User's rights and interests. Analytics technologies requiring consent are activated only after it has been obtained.
Purpose: sending OTP codes, confirmations, and information about payments, the Menu, the Cut-off, Package changes, delivery, security and complaints.
Basis: performance of the contract, security and legal obligations.
Purpose: sending offers and information about Mealzo via e-mail, SMS, LINE, PUSH or other chosen channels.
Basis: consent, where required. Each channel should be managed separately.
Purpose: informing you that Mealzo has started delivering to the indicated address or district, and analysing demand for further Zones.
Basis: the consent of the person joining the list.
Purpose: accounting, taxes, responses to authorised bodies, documenting consents, keeping records, and pursuing or defending claims.
Basis: legal obligation and legitimate interest.
1. Providing data marked as required is necessary to use a given feature.
2. Without your name, contact details and the information needed for delivery, we may not be able to create an Account, accept an Order or deliver Meals.
3. Without the payment data required by the operator, it will not be possible to pay for an Order using that method.
4. Providing preferences is generally voluntary.
5. Providing allergy or health data is voluntary. However, if the Customer expects Mealzo to take such a restriction into account, the absence of the information or the withdrawal of consent may make it impossible to provide an appropriately modified Package.
6. Marketing consents and consents for optional cookies are voluntary. Their absence should not prevent the purchase of the basic service.
1. We use Account data to identify the Customer, secure access, display the active Package and Order history, and operate the features available after logging in.
2. OTP codes are used to verify the phone number, to log in, or to confirm a specific operation. A code is valid for a limited time and should not be shared with others.
3. If you choose to sign in with Google, Google confirms your identity and Mealzo receives the data shared in accordance with the sign-in screen. Google may act as a separate controller with respect to its own service.
4. Mealzo may restrict access to an Account when it detects suspicious activity. In such a case, we use technical data and activity history only to the extent needed to investigate the event and secure the Account.
1. Mealzo records the configuration of the purchased Package, because without it, it would not be possible to prepare the right number of Meals on the right days.
2. For each Delivery Day, we may record a separate set of data, in particular the Menu, the day's status, the address, the Delivery Zone, the cost, modifications, allergens and instructions.
3. Menu changes, Skips, Pauses, resumptions and address changes are recorded in the history so that Mealzo can correctly settle the Package and clarify any discrepancies.
4. If the Customer does not select a Menu by the Cut-off, the system may assign an Automatic Menu in accordance with the Terms and Conditions. For such an assignment, we use the Package parameters, the available Menu, saved preferences and information necessary for safety.
1. Mealzo uses the exact address and coordinates to check the Delivery Zone, assign the correct kitchen, plan the delivery and confirm the Meal handover location.
2. The Customer may provide the address via a form, a place search, or by moving the pin on the map.
3. The map provider may receive the search query, coordinates, IP address and the technical data needed for the map to work. With respect to its own services, it may act under its own privacy policy.
4. Mealzo records the historical address assigned to a specific Delivery Day. Changing the main address in the profile should not change the data of a historical Order.
5. If an address is outside an active Zone, we may offer to save your phone number or e-mail address on the waiting list. This data is not automatically used for other marketing without an appropriate basis.
1. The available payment methods will be visible before the Order is placed. As at the date of this version of the Policy, the final set of payment operators has not yet gone live.
2. Once payments go live, Mealzo will pass the operator the data needed to initiate and settle the transaction, for example the Order number, amount, currency, contact details and Customer identifier.
3. The operator may pass Mealzo the status, transaction identifier, payment method, date, amount and a token allowing the payment to be securely linked to the Order.
4. Full card details and the security code should be entered directly in the operator's secure environment, not stored by Mealzo.
5. The current list of active payment operators and information about their role should be available next to the payment method and in the current list of processing providers.
1. Mealzo may send messages necessary for providing the service, including:
2. Transactional messages are not marketing. They are needed to provide the service and may be sent even if the Customer has not consented to marketing.
3. If you contact Mealzo via LINE, SMS, e-mail, chat or social media, the provider of the given channel may also process data under its own rules.
4. Customer service staff should only have access to the data needed to resolve the enquiry.
1. Mealzo may send marketing only in accordance with the chosen legal basis and the user's settings.
2. Consents should be separated by channel, in particular:
3. Consent can be withdrawn in the Account settings, via the unsubscribe link, the relevant feature of the given channel, or by contacting Mealzo.
4. Withdrawing marketing consent does not affect messages necessary to fulfil an active Package.
5. Mealzo does not sell personal data to data brokers or advertisers.
6. Allergy and health data is not used for ad targeting.
1. Mealzo may use cookies, localStorage, sessionStorage, application identifiers and similar technologies.
2. Essential technologies may be used for:
3. Analytics, functional or marketing technologies that are not essential should be activated only after the appropriate consent has been obtained.
4. The user should be able to reject optional categories, save their own choice and change their decision later.
5. A detailed list of cookies, their purpose, provider and duration can be found in the separate Cookie Policy and the cookie settings panel.
1. Mealzo may use system rules to:
2. Automatic Menu assignment is based on the Package parameters, dish availability, saved preferences and safety-related information.
3. Mealzo should not make solely automated decisions producing legal effects or similarly significantly affecting the Customer without an appropriate basis and safeguards.
4. In case of doubts about an automatic Menu assignment, the Customer may contact customer service and request an explanation or a correction, where the Cut-off and availability allow.
Mealzo may share data only to the extent needed for a specific purpose. Recipients may include:
1. Mealzo employees and contractors, for example customer service, administrators, the nutritionist, the kitchen, packing, the dispatcher and the driver. Each role should see only the data needed to perform its tasks.
2. Providers of infrastructure, hosting, databases, file storage, CDN, security, monitoring, backups and technical support.
3. Communication providers, including e-mail, SMS, OTP, LINE and PUSH.
4. Sign-in and identity providers, when the user uses external sign-in.
5. Map, geocoding and routing providers, needed for address validation and delivery.
6. Payment operators and banks, once the relevant methods go live.
7. Accountants, auditors, lawyers and insurers, where needed for settlements, compliance, complaints or the defence of claims.
8. Couriers, drivers and delivery partners, if they carry out deliveries on Mealzo's behalf. They should receive only the data needed for the specific route and Meal handover.
9. The company or institution funding the Package, if the Customer participates in a B2B programme. The scope of information visible to the company should be clearly defined before joining the programme and should not include health data without an appropriate basis.
10. Public authorities, courts and authorised institutions, where disclosure is required by law or necessary to protect rights.
11. A business acquirer or legal successor, in the event of a reorganisation, merger or sale of the business, subject to appropriate safeguards.
Mealzo does not share data with a wider circle of recipients merely because it is technically possible.
1. Some providers may independently determine part of the purposes and means of processing. This applies in particular to banks, payment operators, Google, app stores and the communication channels used by the Customer.
2. To that extent, the provider acts under its own privacy policy and is responsible for its own processing.
3. Before launching any integration, Mealzo should assess the scope of data shared and make up-to-date information about the provider available.
1. Some technology providers may store or process data outside Thailand.
2. Mealzo should make such a transfer only where it complies with the PDPA and an adequate level of protection or another legally permissible safeguard is ensured.
3. Depending on the situation, safeguards may include a data protection agreement, recipient commitments, binding corporate rules, a recognised level of protection, or another basis provided for by law.
4. If a transfer requires consent, Mealzo should provide appropriate information about the risk and purpose of the transfer before obtaining it.
5. The current list of the main processing locations and providers should be maintained in Mealzo's documentation and made available on request to the extent required by law.
Mealzo does not retain data indefinitely. The period depends on the purpose, the type of data, legal obligations and risk. We apply the following operational rules, unless the law requires a longer period or a dispute is pending.
1. Account and profile: for the duration of the Account's activity and up to 3 years from its closure or last activity, except for data transferred to Order documentation.
2. Incomplete registration and OTP verification data: as a rule up to 90 days; the codes themselves should expire much earlier, in line with security settings.
3. Orders, Packages, payments and accounting documentation: for the period required by tax, accounting and consumer regulations, with a working assumption of at least 5 years from the end of the relevant accounting period, unless the law requires longer.
4. Addresses saved in the profile: until they are deleted, the Account is closed, or 3 years have passed since the last activity. A snapshot of the address used for a delivery is retained with the Order documentation.
5. Allergy and health data saved in the profile: until consent is withdrawn, the information is deleted, the Account is closed, or the purpose ends. Data linked to a specific Order may be retained for the period needed for safety, complaints and the defence of claims, generally no longer than the documentation of that Order, with restricted access.
6. Complaints and customer service correspondence: up to 3 years from the closure of the case, and longer if a dispute is pending or regulations so require.
7. Technical and security logs: generally up to 12 months, unless longer retention is needed to investigate an incident, detect fraud or defend claims.
8. Evidence of consents and document acceptances: for the duration of the consent or contract and up to 5 years after its end, unless a longer period is required.
9. Marketing data: until consent is withdrawn, an objection is raised, or after 24 months of inactivity, after which the consent should be reassessed or the data deleted.
10. Delivery Zone waiting list: up to 12 months or until earlier withdrawal of consent.
11. After the period expires, data is deleted, destroyed or anonymised, unless its continued retention has a separate basis.
12. The periods should be approved before publication by a Thai lawyer and accountant and reflected in the system's retention schedule.
1. Mealzo selects technical and organisational measures appropriate to the type of data, the scale of the business and the risk.
2. The measures should include in particular:
3. No system provides a complete absence of risk. Mealzo should, however, regularly assess its safeguards and remedy identified weaknesses before releasing new features.
4. The Customer should protect their password, OTP code and device, and immediately report any suspected Account takeover.
1. Mealzo should have a procedure for detecting, assessing, documenting and mitigating the effects of data breaches.
2. If a breach meets the conditions set out in the PDPA, Mealzo notifies the competent authority within the legally required deadline and, in high-risk situations, also informs the data subjects.
3. The notification to the individual may include the nature of the event, the possible consequences, the measures taken, recommended protective steps and contact details.
4. A user may report a suspected breach to hello@mealzo.store. Once a dedicated security channel is launched, its details should replace this address in the Policy.
To the extent provided for by the PDPA, you may ask Mealzo for:
1. Withdrawal of consent at any time, where processing is based on consent.
2. Access to your data and a copy of the data processed by Mealzo.
3. Information about the source of the data, if it was not collected directly from you, subject to legal exceptions.
4. Rectification of data that is incorrect, outdated or incomplete.
5. Deletion, destruction or anonymisation of data, when it is no longer needed, consent has been withdrawn, an effective objection has been raised, or the processing is unlawful.
6. Restriction of the use of data in the cases provided for by law.
7. Data portability in a readable format, or transfer to another controller, where the legal and technical conditions are met.
8. Objection to processing based on a legitimate interest or carried out for direct marketing purposes.
9. Lodging a complaint with the Office of the Personal Data Protection Committee if you believe Mealzo is violating the PDPA.
10. These rights are not absolute. Mealzo may refuse to fulfil a request in whole or in part where a legal basis exists, for example an obligation to retain data, protection of the rights of others, security, or the defence of claims. In such a case, we should state the reason, where the law permits.
1. A request can be sent to hello@mealzo.store or via the privacy feature in the Account, once it is implemented.
2. The message should include:
3. Mealzo may ask for additional identity confirmation. It should not request more data than is needed to safely fulfil the request.
4. Requests are handled without undue delay and within the deadline required by the PDPA.
5. Exercising your rights is, as a rule, free of charge. In cases permitted by law, Mealzo may refuse a manifestly unfounded or excessive request, or charge a reasonable fee, after prior notice.
6. An authorised representative may act on a person's behalf after presenting appropriate authorisation.
1. Mealzo is intended primarily for persons aged 20 or over.
2. A younger person should not independently create an Account or purchase a Package without the involvement of a parent or legal guardian, where their consent is legally required.
3. Mealzo does not direct profiling-based advertising at children.
4. If we learn that we have collected a minor's data without the required consent or basis, we will take steps to delete it or to properly regularise the processing.
5. If Plans intended for children are created in the future, separate rules on consent, food safety and data protection will be implemented before their launch.
1. If Mealzo launches a corporate programme, employee data may be processed on the basis of:
2. The company may receive the information needed to manage the programme, for example participation status, the number of Meals used, the subsidy amount, the department or cost centre.
3. The company should not receive detailed data about allergies, health, private preferences or the employee's exact Menu, unless there is a clear, lawful need and an appropriate basis.
4. Before launching B2B, Mealzo should provide employees with an additional notice describing the roles of Mealzo and the employer, the scope of data sharing and the subsidy rules.
1. If you believe that Mealzo is processing your data improperly, please contact us first so that we can clarify and fix the problem.
2. Regardless of contacting Mealzo, you have the right to lodge a complaint with the Office of the Personal Data Protection Committee in Thailand, in accordance with that authority's current procedure.
3. Lodging a complaint does not deprive you of other remedies provided for by law.
1. Mealzo may update this Policy, in particular following changes to its services, providers, the law, Delivery Zones, payment methods or the way data is processed.
2. Each version should have a number, a publication date and an effective date.
3. In the event of a material change, Mealzo should inform users via the website, the Account, e-mail or another appropriate channel.
4. If a new purpose requires consent, Mealzo will obtain it before starting such processing.
5. Older versions should be archived so that it can be established which information applied at a given time.
1. This Policy may be made available in Thai, English, Polish, German, French, Russian and Simplified Chinese.
2. All versions should convey the same meaning and may not be automatically deemed approved without linguistic review.
3. For business conducted in Thailand, the target Thai version should be reviewed by a Thai lawyer and designated as the prevailing version, provided the lawyer confirms the correctness of such an arrangement.
For matters concerning personal data, consents or the exercise of rights, Mealzo can be contacted at:
E-mail: hello@mealzo.store
If Mealzo appoints a Data Protection Officer or a dedicated privacy team, their current contact details will be provided here.