KPG Meal Prep

Privacy policy

Last updated 5 September 2026. This policy replaces the one KPG Meal Prep inherited from its previous ordering platform, which described a different company in a different country.

KPG Meal Prep is a meal-prep kitchen and delivery service on Koh Phangan, Thailand. We cook, pack and deliver the food ourselves, and we run the website, the customer account, the kitchen system and the driver app at phanganmealprep.com. For the purposes of Thailand’s Personal Data Protection Act B.E. 2562 (2019) (the “PDPA”), we are the data controller for everything described below. Thai law governs this policy.

This page describes what our systems actually hold and do, not what a template says they might. If something here does not match your experience, please tell us.

What we collect

Your account

  • Your name, e-mail address, phone number and preferred language.
  • Your password, stored only as a one-way hash. Nobody here can read it, including us.
  • If you turn on two-factor authentication, the secret your authenticator app uses and your backup codes.
  • A record of each sign-in session: when it started, when it expires, the IP address it came from and the browser it used. You can see and end your own sessions.
  • If you choose to sign in with Google or LINE, the name, e-mail address and profile picture that provider gives us. These sign-in options are not switched on yet.

Where we deliver

  • Each delivery address you save, in the format your country uses — house or building details, sub-district, district, province, postcode, and the recipient’s name if it is not yours.
  • A contact phone number for that address, if you give one.
  • Delivery instructions and gate or access notes you write for the driver.
  • A map pin. On Koh Phangan an address text is often not enough to find a door, so every address carries a latitude and longitude, and you can drag the pin to the exact spot. That pin is what the driver navigates to.

What you order

  • Your carts, orders, subscriptions, meal selections, invoices, coupons and any store credit.
  • The delivery date and time window you chose, the delivery’s status, any delivery attempt that failed and why, and the time it was handed over.
  • A snapshot of the address and the meals as they were at the moment you ordered, so an old order still shows what you actually bought.
  • Proof of delivery: a photograph, or a signature or PIN stored only as a one-way hash, together with the time and the driver’s location at handover.

What you eat

  • Your goal, and any calorie and macronutrient targets you set.
  • Diet preferences, ingredients you dislike, and meals you mark as favourites or rate.
  • Allergens you tell us to avoid. Information about allergies is health information, and the PDPA treats it as sensitive. We ask for it only so your meals can be chosen and prepared with it in mind, we use it for nothing else, and we hold it because you gave it to us deliberately. You can remove it from your profile at any time.

We publish the ingredients and the calculated nutrition of every meal, and we tell you which of the fourteen listed allergens a recipe contains. We do not tell you that a meal is free of an allergen: our kitchen is a single kitchen and we will not make a claim we cannot guarantee. If an allergy is serious, please talk to us before you order.

Paying

  • We never receive, see or store your card number, expiry date or security code. When card and PromptPay payments are switched on they run through Stripe, and your card details go from your browser to Stripe without passing through us. We keep Stripe’s reference for the payment, the amount, the currency, whether it succeeded, and the reason if it did not.
  • Today we take bank transfer, PromptPay entered by hand, and cash. For those we keep the amount, the payment reference or slip note you give us, and which member of staff recorded it.
  • Invoices, refunds and the reasons for them.

Messages

  • Which channels you want to hear from us on — e-mail, LINE, WhatsApp, browser notifications — for each kind of message, and when you switched each one on.
  • The messages we send you, including their full text, so we can show you what was sent and see whether it arrived.
  • Your LINE user ID, if you link LINE. Your phone number and the time you opted in, if you choose WhatsApp. The browser push keys for each device you allow notifications on.
  • Marketing e-mail only if you have asked for it, and you can stop it in one click.

When you contact us

  • Messages you send through the contact form, by e-mail, or on LINE or WhatsApp, including your name, the address or number you wrote from, and everything in the message.
  • Our replies, and which member of staff answered.
  • Notes and labels our staff add to your account — for example that you prefer an early delivery window, or that a previous order went wrong. These are internal, and they are written on the understanding that you may ask to see them.

Technical records

  • Your IP address and browser, recorded against each sign-in session and against administrative actions in our audit log.
  • Counters that limit how often sign-in, the contact form and the help assistant can be used from one address, to stop abuse.
  • Crash reports when something goes wrong, with secrets stripped out before they are stored.

Why we use it, and on what legal basis

  • To perform our contract with you — taking your order, cooking it, routing it, delivering it, billing it, and answering you about it. Without your name, address, pin and phone number we cannot deliver food to you.
  • Because you consented — marketing messages, WhatsApp and browser notifications, and the dietary and allergen information in your profile. You can withdraw any of these at any time, and withdrawing does not affect anything we did before you did.
  • Because the law requires it — keeping invoices, payment records and tax documents for the period Thai accounting and revenue law prescribes.
  • Because we have a legitimate interest — keeping the service secure, preventing fraud and abuse, keeping an audit trail of administrative changes, and understanding in aggregate which meals sell so we cook the right amount. We do not profile you for advertising, and we do not sell or rent your data to anyone.

Who can see it

Our staff

Every screen and every API route in our system checks a permission before it answers. Staff see only what their role allows, and the check happens on our server, not in the browser, so hiding something in the interface is not the only thing standing between a person and your data.

In particular, seeing a customer’s e-mail address or phone number needs a separate permission from seeing that the customer exists. Staff without it see the account, the orders and the delivery history with the contact details blanked out, and any spreadsheet they export has those columns blanked too. Every export and every download of one is logged.

Our delivery drivers

A driver on a route sees, for each stop on that day’s run: your first name, your phone number, your delivery address, the map pin and your delivery instructions, plus the order number and how many boxes to hand over. This is deliberate — a driver who cannot call you cannot deliver to you.

A driver does not see your surname, your e-mail address, what you paid, your other orders, or anyone else’s deliveries. Their app shows your number partly hidden until they tap to call or message you.

Anyone you send a tracking link to

A delivery tracking link is tied to that one delivery and expires twenty-four hours after its window ends. It shows the delivery’s status and estimated time and the driver’s first name. It does not show your address, your name, the order value, or any other delivery. We can revoke a link at any time.

Companies that process data for us

We use a small number of service providers, and we send each of them only what it needs. Some are outside Thailand, so using our service involves an international transfer of your data; we choose providers that commit to appropriate safeguards.

  • Stripe — card and PromptPay payments. Receives the amount, the currency and your e-mail address for the receipt. Not switched on yet.
  • Our e-mail sender — receives the address we are writing to and the content of the message.
  • LINE and WhatsApp (Meta) — receive your LINE user ID or your phone number and the message text, and only if you have linked that channel yourself. Not switched on yet.
  • Your browser’s push service (Google, Mozilla or Apple, depending on your browser) — receives an encrypted notification if you allow browser notifications.
  • Object storage — holds meal photographs, proof-of-delivery photographs and any spreadsheet an operator exports. Files are served through short-lived signed links, not public URLs.
  • OpenStreetMap — draws the map you pin your address on. Your browser fetches the map tiles directly, so OpenStreetMap sees your IP address and roughly which area you are looking at. This one is active today.
  • Cloudflare Turnstile — an anti-bot check on sign-up and the contact form, which would receive your IP address. Currently switched off.
  • Sentry — crash reporting. Currently switched off.
  • Anthropic — the help assistant on the site. If you ask it about your own account it may read your own orders, deliveries and subscription in order to answer; it is never given your address, e-mail or phone number, it cannot change anything, and it cannot see anyone else’s account. Currently switched off.

Cookies

We set a session cookie when you sign in, and short-lived cookies during sign-in and two-factor verification. They are marked httpOnly, so a script cannot read them, and they exist only to keep you signed in.

We use no advertising cookies, no analytics cookies and no third-party trackers. That is why this site has no cookie consent banner: there is nothing to consent to beyond the cookie that signs you in.

How long we keep things

  • Your account, addresses and dietary profile — for as long as you have an account, and until you ask us to remove them.
  • Orders, invoices, payments, refunds and deliveries — kept permanently. They are an immutable financial and food-safety record: we never delete or rewrite them, both because Thai accounting and tax law requires us to keep them and because a kitchen must be able to trace what it cooked and where it went.
  • Sign-in sessions — up to 30 days, then they expire on their own. Ending a session removes it immediately.
  • Support conversations — kept while they are useful; messages from people who are not customers are removed after 90 days.
  • Driver GPS breadcrumbs — the trail of a driver’s position during a route is deleted automatically after 14 days. The delivery’s own events and its proof of delivery are kept with the order.
  • Delivery tracking links — expire 24 hours after the delivery window ends.
  • Notifications we sent you — kept with your account so we can show you what was sent.
  • Audit and security logs — our retention period is 24 months. Older records are removed on review rather than automatically.

Your rights

Under the PDPA you may ask us to:

  • tell you what personal data we hold about you, and give you a copy of it;
  • correct anything that is wrong or out of date — you can edit your own profile, addresses, dietary information and message preferences at any time in your account;
  • delete or anonymise your data, within the limits described below;
  • stop or restrict a particular use of it;
  • withdraw a consent you gave, such as marketing, WhatsApp or notifications;
  • object to a use we base on our legitimate interest;
  • receive the data you gave us in a portable form.

How to ask

Two of these you can now do yourself, without asking anybody, from Your data in your account. Everything else — correction, restriction, objection — still goes through the contact page, is read and carried out by a person, and is answered within 30 days.

Getting a copy of your data

Your account → Your data → “Request my data”. We build a machine-readable file (JSON) and give you a download link that expires after a short time; ask for a fresh link whenever you need one. It is prepared in the background, so it appears a moment after you ask.

The file contains your account details, your sign-in identities and sessions, your goals, diet preferences and allergens, your saved addresses and map pins, your shopping carts, your orders and their lines and status history, your invoices, payments, payment attempts and refunds, your saved payment methods, the coupons you used, your deliveries with their events and proof of delivery, your meal plan subscriptions with their timeline, weeks and the meals you chose, your store and meal credits, the meals you favourited and rated, the tags and notes our staff have attached to your account, the announcements you dismissed, how you asked to be contacted, your registered notification devices, the messages we sent you, and your conversations with our support team.

Four things are deliberately not in it. Your password, two-factor secret and backup codes are stored only as one-way hashes and cannot be read back — not by you and not by us. Card numbers never reach our systems. Other people are not named: if you referred somebody, or somebody referred you, the file shows only that a referral exists. And internal system records that are not about you personally — server logs, background jobs and our audit trail — are not included; the audit trail records record identifiers rather than names, which is why it does not need to be.

Asking us to erase you

Your account → Your data → “Erase my account”. You type the confirmation word, and the page shows you, line by line, exactly what will happen to each thing we hold. If a request reaches us by e-mail instead, a member of staff carries out the same operation on your behalf.

It does not happen immediately. A confirmed request is scheduled a set period ahead — seven days unless we have changed that setting, and the page tells you the date — and you can call it off at any point before then. Once it runs it cannot be undone, and you will not be able to sign in again.

When it runs, we remove or replace: your name, e-mail address, phone number and date of birth; your LINE identity and WhatsApp opt-in; your marketing consent; your referral code; the street, sub-district, postcode, recipient and delivery instructions of every saved address, and the address text and map pin stored on each past order and delivery; the comments you left on meal ratings; the messages we sent you, whose text and recipient are replaced; your notification preferences and registered devices; every public delivery-tracking link; the photographs taken at handover, which are deleted from storage; your support conversations, whose contents are emptied by a one-way redaction our database will not let anyone reverse; and your password, two-factor secret, connected sign-in accounts and every active session.

Your allergen and dietary information is deleted outright rather than blanked, because information about your health deserves that.

What we cannot delete

We do not delete the orders, invoices, payments, refunds and deliveries themselves, or the meal plan weeks behind them. Those are the business’s own financial and delivery records, kept for the reasons given above — but after an erasure they no longer say who you were. What survives is the transaction: what was bought, what it cost, when it was delivered and whether it arrived.

Two things are kept in a reduced form rather than removed, and we would rather say so than let you discover it. The district and province of a past delivery are kept, and its map pin is rounded to roughly a kilometre — a neighbourhood, not a door — so that our delivery records still make sense. And your meal rating scores are kept as anonymous numbers once the words you wrote have gone.

One thing we cannot yet erase, and will not pretend otherwise: notes our staff wrote about your account are stored in a form our database makes append-only, so they can be neither edited nor deleted today. They are included in your data export, so you can at least see them. Changing that needs a change to how those notes are stored, and it is on our list.

Complaints

If you are not satisfied with how we have handled your data or your request, you may complain to the Personal Data Protection Committee (PDPC) in Thailand. We would rather you told us first, so that we can put it right.

How we protect it

  • Passwords are stored as one-way hashes and are never recoverable. Signatures and delivery PINs are stored the same way.
  • Staff whose role can move money, change permissions or alter settings must use two-factor authentication.
  • Every permission is checked on our server. Every administrative change is written to an audit log that cannot be edited or deleted.
  • We also record when a member of staff looks at customer data. Listing or opening customer records, addresses, phone numbers or order history writes a line saying who looked, when, from what address, and which records — by their internal identifiers and how many, never by name. This is what lets us answer “what did this account actually see?” if an account is ever misused, and it is deliberately written so that the record of the look is not itself a second copy of your details.
  • Files are stored privately and served through links that expire in minutes.
  • Traffic between your browser and us is encrypted.

No system is perfect. If you think an account has been misused, tell us at once and we will end its sessions and investigate.

Children

This service is not aimed at children, and we do not market to them. Where a customer is a minor, the PDPA may require a parent or guardian to give consent on their behalf. If you believe a child has given us personal data, tell us and we will remove what we are able to.

Changes to this policy

When we change this page we will update the date at the top. If a change materially affects how we use your data, we will tell you by e-mail or in your account before it takes effect.

Contacting us about your data

Use the contact page, or reply to any e-mail we have sent you. We will pass the request to the person responsible for data protection at KPG Meal Prep.