Skip to main content
Tell us
Back office

Customer data and PDPA: a list spread across five places is a list you can't use

A nail salon owner wants to message customers she hasn't seen in three months. The names are in a notebook, LINE chats, an ex-employee's spreadsheet and several people's phones. Two hours later she has forty names and isn't sure she can message any of them.

The woowey team · 6 min read
A fountain pen on an open notebook
Photo: David Travis / Unsplash

Key points

  • A customer list spread across notebooks, chats and staff phones is hard to use for news or follow-up until it's brought together in one place.
  • Most service businesses only use a few fields: name, contact details, past services, care notes and whether the customer agreed to receive news.
  • At small-shop level, PDPA principles mean telling customers what you collect and why, using it only for that, keeping it safe, and acting when customers ask to see, correct or delete their data or withdraw consent.
  • Consent for promotions should be asked for separately from booking, for example with an unticked checkbox, and the date of consent should be recorded.
  • Health information, such as clinic treatment records, is sensitive data under Thai law, so clinics should get professional advice on how to keep it.

It's the end of September, and the owner of a nail salon wants to message customers who haven't been in for three months to tell them the new designs have arrived. Simple enough, until she has to work out who those customers are.

The first list is the appointment book on the counter. Some pages only have a nickname and a time; one had water spilled on it and can't be read. The second is the shop's LINE chats, where customers go by a flower, a line of Japanese characters or the name of their cat. The third is a spreadsheet a former employee made before she left. And half the regulars message the nail techs directly, on the techs' own phones.

Two hours later she has forty names. She doesn't know if half of them are still customers, and she isn't sure about a single one whether they ever said they'd like to hear from the shop. The message never goes out.

The salon has hundreds of customers, yet on the day it wants to use its customer list, none of it is usable. A customer list really is an asset, but only once it's kept properly, in one place, with the customer's consent.

A customer list spread across five places is worth less than one complete list

A scattered list has bigger problems than being hard to find. The same name sits in three places with three different phone numbers. A customer tells one nail tech she reacts to a certain glue, and the other tech never hears about it. A customer who asked to stop getting promotions is still in someone else's file, and that person has no idea.

The most worrying part is the lists on staff's personal phones. The day someone leaves, every customer they looked after leaves with them, and the shop has no way of knowing what happens to that information next.

So the first step doesn't involve software at all. It's agreeing as a team that from now on, customer information lives in one place. Whoever takes on a new customer writes it there. Whoever learns something new adds it there.

Keep only what you'll use. A short, complete record beats a long, messy one

Once shops decide to collect data, many want everything: birthdays, addresses, jobs, income, none of which they ever use. Information you collect and never use is a risk you look after for nothing in return.

For most service businesses, the information that actually gets used fits in a few fields.

  • The name the customer likes to be called, and how to reach them, like a phone number or LINE
  • Services they've had, and when they last came in
  • Notes that help you look after them, like allergies or a favourite staff member
  • Whether they've agreed to hear from the shop, and when they agreed

This lines up with one of the principles of Thailand's personal data law, too: collect only what you need for the purpose you've told customers about.

PDPA for small shops, in plain language

PDPA is Thailand's Personal Data Protection Act B.E. 2562 (2019). Plenty of small shops assume it's for big companies, but any business that keeps customers' names, phone numbers or service history is handling personal data. At the level of principles, there are a handful of things a shop should know.

Tell customers what you collect and why. For example, a phone number to confirm and remind them about bookings, and service history to look after them next time. A short note on the booking page or a sign at the counter will do.

Use it for what you said. If you collected a phone number for booking reminders and want to send promotions to it, ask for consent separately. And don't hand your list to another business.

Keep it safe. Limit who can see it, don't leave the customer book open where other customers can read it, and keep it off personal devices the shop has no control over.

Act on what customers ask for. Customers can ask to see what you hold about them, ask you to correct it or delete it, or withdraw their consent. The shop should know in advance what it will do when someone asks.

Shops that hold health information, like clinics, need to take extra care, because the law treats health data as sensitive data with stricter conditions. This article only covers the principles. If your shop holds that kind of data, or you're unsure what applies to you, talk to a lawyer or a personal data specialist directly.

The best moment is when the customer is already giving you their details: while booking, or on their first visit. Not in a separate message later.

On an online booking page, that might be a separate checkbox saying "I'd like news and offers from the shop on LINE", left unticked. Customers who don't tick it can still book as normal. At the counter, you can ask the same question in person and note the answer next to the customer's name, with the date.

Say clearly what you'll send and how often. "New designs and the monthly offer, no more than twice a month" is far more comfortable to agree to than "I consent to the shop using my data for marketing purposes". And customers who said yes to the first kind of wording rarely mind when the messages arrive.

Customer data shouldn't live on staff's personal phones

For small shops, data security is rarely about hackers. It's far more ordinary: a customer book left open on the counter, a file passed around in a group chat, one password the whole shop has shared for five years, and a former employee who's still in the shop's LINE group.

A few things can be done right away. Have customers contact the shop through the shop's own account, not staff's personal numbers. Keep the list in one place where you control who can see it. Remove people who leave from every group and account on the day they go. And keep a backup, for the day a phone breaks or a file disappears.

Data you no longer use should be deleted, both for customers who ask and for old records there's no reason to keep. The less you keep, the less you have to look after.

Once the list is in one place, with consent, the shop can start using it

Well-kept customer data changes a lot at the front desk. The nail tech can see before the customer arrives which design she had last time and which glue she reacts to. The shop can see who hasn't been in for a while and check in on them. And news goes only to people who agreed to it, with no worrying about who might be annoyed.

That same data is the foundation of making customers feel the shop remembers them, which works far better than points. We write more about that in memberships and points: do they bring customers back. And if you're thinking about using customer data with AI, read what to share with AI and what to keep out first.

For shops that have their website and booking system with woowey, customer details from bookings and website forms are kept in one place and backed up every day, so nobody has to piece the list together from chats.

At the end of next month, if that nail salon owner wants to tell customers the new designs are in, she'll open one list, see who hasn't been in for three months and agreed to hear from her, and start messaging. No guessing who's okay with it.

Frequently asked questions

Does PDPA apply to small shops?

Generally, yes. A shop that keeps customers' personal data, such as names, phone numbers or service history, falls under Thailand's Personal Data Protection Act. Exactly which duties apply depends on the size of the business and the type of data, so get professional advice for your case.

Can I send promotions to phone numbers I got from bookings?

Ask for consent first. Those numbers were collected to confirm and remind customers about bookings, and promotions are a different purpose. Make it as easy to opt out as it was to opt in.

What should I do if a customer asks me to delete their data?

Delete it or stop using it as they ask, except for anything you're legally required to keep. If you're unsure what you can keep, ask a professional.

What customer information should a shop keep?

Only what you'll use. For most service businesses that's a name, contact details, past services, the last visit date, care notes such as allergies, and whether the customer agreed to receive news.

The woowey team

We build websites and systems for businesses

We build websites, booking systems, online stores and back offices for Thai businesses, then look after them every month. What we write here comes from what we see working with real shops.

Want this for your business? Tell us

Type what you need. The woowey team builds your website and systems, then looks after them every month.

กดเพื่อส่ง หรือลากออกแล้วปล่อย