Hello Europe · Passport

Privacy Policy

How Hello Europe collects, uses and protects information when you use our website or Hello Europe Passport.

Effective 10 August 2026

1

Who is responsible for your data

Hello Europe is the data controller for the Hello Europe website and Passport membership programme.

Business address: RX54+G2H Kad Na Mor Market, Huay Kaew Rd, Chang Phueak, Chiang Mai, Thailand, 50300

Privacy contact: whereismaco@gmail.com

2

Data we collect

  • OAuth identity information supplied by Google or LINE, such as provider user ID, display name and, where authorised and available, email address.
  • Optional phone number entered without Thailand’s +66 country code.
  • Passport member code, private QR token, preferred language, account status, point balance and point ledger.
  • Orders linked to your Passport, purchase channel, amount, products, toppings, date and time.
  • Grab order references and information needed to review a points claim.
  • Technical information such as session cookies, IP address, browser/device information, security logs and website interaction events.
3

Why we use your data

  • To create, authenticate and secure your Passport account.
  • To identify you at our stand by QR code, member code or phone number.
  • To calculate points, maintain an auditable point history and correct modified or cancelled orders.
  • To verify eligible Grab claims, prevent duplicate claims, fraud and misuse.
  • To operate, protect and improve the website, membership programme and customer experience.
  • To meet accounting, tax, consumer-protection and other legal obligations.
4

Legal grounds

We process data as necessary to provide the Passport service you request, to comply with legal obligations, and for legitimate interests such as service security, fraud prevention and programme administration. Where applicable law requires consent—for example for optional analytics or marketing—we rely on consent and you may withdraw it without affecting earlier lawful processing.

5

Service providers and disclosures

We do not sell personal data. We disclose only what is reasonably necessary to providers that help us operate the service, including:

  • Google and LINE for sign-in, under their own privacy terms.
  • Our website host, database and technical service providers.
  • Google Tag Manager and configured analytics services for website measurement.
  • Grab information supplied by you when we verify a Grab order claim.
  • Authorities or professional advisers where required by law or necessary to protect legal rights.
6

Cookies and analytics

Essential cookies keep sign-in sessions secure and connect your browser to your Passport account. Google Tag Manager is used to manage website measurement tags; configured analytics tools may collect page, device, approximate location and interaction data and may set cookies. You can restrict cookies in your browser, but blocking essential cookies can prevent sign-in from working.

7

International processing

Google, LINE, hosting or analytics providers may process data outside Thailand. Where data is transferred internationally, we use providers and safeguards intended to provide appropriate protection under applicable law.

8

Retention and security

We retain Passport information while the account is active and afterwards only for as long as reasonably needed for programme administration, disputes, fraud prevention and legal record-keeping. Order and accounting records may be kept for the period required by law. We use access controls, encrypted connections, non-guessable QR tokens and restricted administrative access, but no online system can guarantee absolute security.

9

Your privacy rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also request account deactivation or a new QR token and may complain to Thailand’s Personal Data Protection Committee. Contact us at whereismaco@gmail.com. We may need to verify your identity before completing a request.

10

Children and policy updates

The Passport is not designed to collect data from children who cannot lawfully consent without a parent or guardian. We may update this notice when the service or law changes. The newest version and effective date will always appear on this page.