Loading...
Loading...
Loading...Last updated: August 14, 2026
This Privacy Policy explains how CrazyBKK.com (hereinafter referred to as the "Website", the "Platform", or "we") collects, uses, and protects users' personal data, in accordance with applicable data protection laws, including the Swiss Federal Act on Data Protection (FADP) and, where applicable, Regulation (EU) 2016/679 ("GDPR").
The Data Controller responsible for the processing of personal data is, as of the date of this Privacy Policy, an individual residing in Switzerland:
Vincenzo Postiglione
Owner of CrazyBKK.com
Switzerland
Email: admin@stadlio.com
The Data Controller is established in Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection for the purposes of Article 45 GDPR.
CrazyBKK.com is accessible internationally and may be directed, depending on its services and activities, to users located in Thailand, Switzerland, the European Union, and other countries. The GDPR may therefore apply to certain processing activities where its territorial scope requirements are met, while the Swiss FADP applies where relevant to the activities of the Data Controller.
Technology platform: the Platform is developed and operated using the Stadlio technology infrastructure. Where Stadlio processes personal data on behalf of the Data Controller, it acts as a processor or service provider under an appropriate contractual arrangement.
Where Article 27 GDPR requires the appointment of a representative in the European Union, the Data Controller will appoint an appropriate EU representative before or when such an obligation becomes applicable.
Unless and until such a representative is formally appointed and identified in this Privacy Policy, requests relating to personal data should be sent directly to:
For transparency, the Operator may in the future reorganise the business activities relating to CrazyBKK.com or transfer the operation of the Platform to another company or legal entity.
Such a reorganisation may include the incorporation of a company within Switzerland, the European Union, or another jurisdiction appropriate for the operation of the Platform.
Where the identity of the Data Controller changes as a result of a corporate restructuring, merger, acquisition, business transfer, or similar transaction:
users will be informed where required by applicable law;
this Privacy Policy will be updated with the identity and contact details of the new Data Controller;
the purposes and legal bases of processing will remain unchanged unless users are informed otherwise;
any transfer of personal data will be carried out in accordance with applicable data protection laws.
We may collect and process the following categories of personal data.
Registration data: first name, last name, email address, password stored in encrypted or hashed form, and optional telephone number;
User profile data: preferences, interests, language, profile picture where uploaded, and activity history on the Platform;
Booking and enquiry data: name of the person making the booking or request, number of persons, requested date and time, special requests, and other information voluntarily provided through booking or contact forms. Payment information, where applicable, is handled by the relevant payment provider, such as Stripe;
Business and billing data: for Merchants and business users, company name, tax or registration number where applicable, registered business address, billing information, and payment details where necessary for the relevant service;
User-generated content: reviews, comments, messages, photographs, and other content submitted through the Platform.
Browsing data: IP address, browser type, operating system, pages visited, date and time of access, referring URL, and session identifiers;
Technical data: device type, screen resolution, browser language, application version, and technical information necessary for the operation and security of the Platform;
Cookies and identifiers: as described in Section 11 and in our Cookie Policy.
If you choose to register or log in through third-party authentication services, such as Google or another supported login provider, we may receive the minimum information necessary to create or manage your account, such as your email address and public name, according to the permissions you grant to the relevant service.
Where the GDPR applies, we process personal data only for the purposes described below and on the relevant legal basis under Article 6 GDPR.
Purpose Legal basis where GDPR applies Creating and managing a user account Performance of a contract — Article 6(1)(b) GDPR Managing booking requests, enquiries, and requested Platform services Performance of a contract or steps taken at the user's request before entering into a contract — Article 6(1)(b) GDPR Sending service communications, confirmations, reminders, or changes Performance of a contract — Article 6(1)(b) GDPR Sending newsletters and promotional communications Consent — Article 6(1)(a) GDPR, where required; consent may be withdrawn at any time Website and application analytics Consent for non-essential cookies where required — Article 6(1)(a) GDPR; legitimate interests for appropriately configured aggregated or strictly necessary analytics where permitted — Article 6(1)(f) GDPR Preventing fraud, abuse, security incidents, and unlawful activity Legitimate interests — Article 6(1)(f) GDPR, or compliance with legal obligations where applicable Complying with tax, accounting, legal, and regulatory obligations Legal obligation — Article 6(1)(c) GDPR Managing relationships with Merchants, including subscriptions and billing Performance of a contract — Article 6(1)(b) GDPR and compliance with applicable legal obligations
Where Swiss data protection law applies, we process personal data in accordance with the applicable principles and requirements of the Swiss FADP.
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected and, where applicable, to comply with legal obligations.
User account data: for the duration of the user relationship and generally for up to 12 months after a deletion request or prolonged inactivity, unless a longer retention period is required or justified by law;
Booking, transaction, and billing data: for the period required by applicable tax, accounting, contractual, or legal obligations, which may generally extend up to 10 years depending on the applicable law and circumstances;
Merchant business and billing data: for the duration of the commercial relationship and thereafter for the period required by applicable accounting, tax, or legal obligations;
Technical and security logs: generally for up to 12 months, unless a longer period is necessary for security, incident investigation, or legal claims;
Newsletter data: until consent is withdrawn or the user unsubscribes and, in any event, subject to periodic review of whether continued retention is necessary;
Cookies: according to the durations described in our Cookie Policy.
At the end of the applicable retention period, data is securely deleted or irreversibly anonymised, unless further retention is required or permitted by applicable law.
Personal data may be shared with:
Merchants and local businesses listed on the Platform, only where necessary to process a booking request, enquiry, or other request initiated by the user;
Technology and service providers, including hosting, infrastructure, email, payment, analytics, and security providers, acting as processors or independent controllers depending on the relevant service and processing activity;
Public authorities, where required by applicable law, a court order, or another legally binding request, or where necessary to protect rights, security, or the integrity of the Platform;
Professional advisers, including accountants, lawyers, auditors, or other advisers, where necessary and subject to applicable confidentiality obligations;
Successors or acquiring entities, in connection with a merger, acquisition, corporate restructuring, financing, or transfer of all or part of the Platform's activities, subject to applicable law.
We do not sell your personal data to third parties.
The Platform may use the following service providers and third-party services, depending on the features available and services used by the user:
Stadlio — technology infrastructure used to develop and operate the Platform. Where Stadlio processes personal data on behalf of the Data Controller, it acts as a processor or service provider under the applicable contractual arrangements. Infrastructure may rely on servers operated by Hetzner Online GmbH;
Brevo — newsletter management and transactional email services. Depending on the service configuration, Brevo may process email addresses, communication preferences, and technical information necessary for sending and measuring communications. See Brevo's Privacy Policy;
Google Analytics — where enabled and consented to where required, used to analyse Website traffic and usage. Data processing is subject to the applicable Google service configuration and policies. See Google's Privacy Policy;
Viator — a third-party provider of tours and travel experiences that may be accessible through affiliate or external links on the Platform. If you proceed to book directly with Viator, the booking is governed by Viator's own terms and privacy practices. See Viator's Privacy Policy;
Stripe — online payment services for applicable Merchant subscriptions or other paid services offered by the Platform. Payment card information is generally processed directly by Stripe and is not stored on our servers. See Stripe's Privacy Policy;
Hetzner Online GmbH — hosting and infrastructure services, including servers located in Germany where applicable. See Hetzner's Privacy Policy;
Sentry — application error monitoring and performance diagnostics. Data processed may include technical information, error reports, device information, and pseudonymised identifiers necessary to identify and resolve technical issues;
Firebase Cloud Messaging — where enabled for the mobile application, used to deliver push notifications to users who have granted the necessary device permissions.
Some service providers may process personal data outside Switzerland, the European Economic Area, or the user's country of residence.
Where the GDPR applies and a transfer of personal data to a third country takes place, the transfer will be carried out using an appropriate safeguard under Chapter V GDPR, including, where applicable:
an adequacy decision adopted by the European Commission under Article 45 GDPR;
the EU-U.S. Data Privacy Framework, where applicable to a certified recipient;
Standard Contractual Clauses approved by the European Commission under Article 46 GDPR;
other legally recognised safeguards and, where appropriate, supplementary technical and organisational measures such as encryption or pseudonymisation.
Transfers between Switzerland and jurisdictions recognised as providing an adequate level of protection are carried out in accordance with the applicable adequacy framework and relevant Swiss data protection requirements.
You may request further information about applicable transfer safeguards by contacting us at admin@stadlio.com.
Depending on the applicable data protection law and the circumstances of the processing, you may have the right to:
Access: obtain confirmation as to whether we process your personal data and, where applicable, receive access to that data;
Rectification: request the correction of inaccurate or incomplete personal data;
Erasure: request deletion of your personal data where the applicable legal conditions are met;
Restriction: request the restriction of processing in circumstances provided for by applicable law;
Data portability: receive certain personal data in a structured, commonly used, and machine-readable format where applicable law grants this right;
Objection: object to processing based on legitimate interests or, where applicable, to direct marketing;
Withdrawal of consent: withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
Automated decision-making: where applicable law grants this right, request safeguards in relation to certain solely automated decisions producing legal or similarly significant effects.
You can exercise your rights by contacting us at admin@stadlio.com.
Please clearly identify the right you wish to exercise and provide sufficient information for us to verify your identity and locate the relevant data. Where reasonably necessary and permitted by law, we may request additional information to verify your identity.
Where the GDPR applies, we generally respond within one month of receiving a valid request. This period may be extended where permitted by applicable law, for example due to the complexity or number of requests, and you will be informed where required.
The exercise of applicable data protection rights is generally free of charge. A reasonable fee may be charged or a request may be refused where permitted by law, for example in the case of manifestly unfounded or excessive requests.
You may request the deletion of your account through the account settings where this functionality is available, or by contacting admin@stadlio.com.
Deleting an account normally results in the removal or anonymisation of account-related personal data, subject to data that must be retained for legal, tax, accounting, security, fraud-prevention, or other legitimate purposes described in this Privacy Policy.
The Platform uses cookies and similar technologies, including local storage, pixel tags, SDKs, authentication tokens, and device identifiers, to ensure the proper operation of the Platform, analyse usage, and, where applicable, personalise the user experience.
Cookies and similar technologies may include:
Strictly necessary cookies: required for the operation, security, authentication, and essential functionality of the Platform;
Preference cookies: used to remember settings and preferences;
Analytics cookies: used to understand aggregated or individual usage of the Platform, subject to consent where required;
Marketing and profiling technologies: used to measure campaigns or personalise communications, subject to prior consent where required.
When required by applicable law, non-essential cookies are activated only after the relevant consent has been obtained. You may change your cookie preferences at any time using the "Manage Cookies" option where available.
For further information, please see our Cookie Policy.
The Platform is not intended for children under the age of 16, unless a specific service expressly provides otherwise in accordance with applicable law.
We do not knowingly collect personal data from children under this age without the consent or authorisation required by applicable law.
If a parent, legal guardian, or other authorised person believes that a child has provided personal data to us in violation of applicable law, they may contact us at admin@stadlio.com to request an appropriate review and, where applicable, deletion of the relevant data.
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised access, or disclosure.
These measures may include:
encryption of data in transit through TLS/HTTPS;
password protection using secure cryptographic hashing mechanisms;
access controls and strong authentication for authorised personnel and systems;
periodic backups and disaster recovery procedures;
security monitoring and logging;
periodic security assessments of relevant systems and service providers.
No system can guarantee absolute security. In the event of a personal data breach, we will assess the incident and, where required by applicable law, notify the competent authority and affected individuals within the applicable legal timeframes.
If you believe that the processing of your personal data violates applicable data protection law, you may have the right to lodge a complaint with the competent supervisory authority.
For users subject to the GDPR: you may contact the data protection supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement, in accordance with Article 77 GDPR;
For users in Switzerland: you may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC), where applicable.
This does not affect any right you may have to seek a judicial remedy.
This Privacy Policy may be updated to reflect changes in applicable law, technology, service providers, or the way in which CrazyBKK.com operates.
Material changes may be communicated through a notice on the Platform and, where appropriate or required by law, by email to registered users.
The date of the latest update is shown at the beginning of this document. Users are encouraged to review this Privacy Policy periodically.
If you have any questions about this Privacy Policy or the processing of your personal data, please contact:
Data Controller
Vincenzo Postiglione
Owner of CrazyBKK.com
Switzerland
Email: admin@stadlio.com
Depending on your cookie choices, we may use these processors for measurement or advertising: