What we collect, and what we do not
No cookies, no third party tracking, no advertising scripts. Here is the whole list, and how to have any of it deleted.
Last updated 28 July 2026
Read this first
This is a draft prepared by the founder and it has not been reviewed by a lawyer, so it is not legal advice. Two things in particular need professional review before GoNow takes any money: whether arranging or being paid for trips in Thailand requires a licence under the Tourism Business and Guide Act, and whether the liability and indemnity wording below is enforceable. GoNow is also not yet an incorporated company, so it is currently an individual, and these limits protect an individual far less than they would protect a company.
What data we collect
We keep this deliberately small.
Usage signals. When you use the map we record which pages were viewed, which places were opened, which searches and filters were used, and when. Each browser session gets a random identifier held only for that session. We do not use cookies, we do not run any third party tracking or advertising script, and we do not attempt to identify you.
What you type into a form. If you tell us which city to cover next, whether you would pay, an optional comment, and an optional email address, we store exactly those fields and nothing else. The same applies to feedback, place suggestions and visit notes you submit.
Your account, if you make one. If you sign in, we store your account identifier and the display name you choose. Signing in with Google tells us your email address and your Google profile name, and nothing else about your Google account.
We do not collect your device identifiers, your contacts, or payment details. We do not sell or rent anything we collect, to anyone, ever.
Data deletion and retention
You may ask us to delete your data at any time, by emailing the address below from the address you gave us, or by describing the submission if you gave no email.
On request, we permanently delete your personal data within 30 days. This means the email address, any comment you wrote, and any submission tied to you are erased from the live database and from backups on their next rotation cycle. We will confirm when it is done.
Retention without a request:
- Usage signals are deleted automatically after 90 days. They carry no personal data and only a per-session random identifier.
- Form entries, including any email, are kept until you ask us to delete them, or until the thing you asked about ships and we have told you, whichever is sooner.
- Aggregate counts (for example, forty people asked for Chiang Mai) are kept indefinitely, because they contain no personal data and cannot be traced back to an individual.
The one exception, stated plainly: where a law, regulator, court order or a legitimate legal claim requires us to keep specific records, we keep only what is legally required, only for as long as it is required, and we isolate it from normal use. We will tell you if this applies to your request. We will not use a legal-retention claim as an excuse to keep data we simply want.
Where the data lives
The site is served as static files. The database is hosted by Supabase. Data may be processed outside your country of residence. We rely on row level security so that public visitors can read only published place information, and can never read back submissions, usage data, or other people's email addresses.
Sign-in is handled by Supabase Auth. Because the site is static and has no server of its own, your session is held in your browser's local storage rather than in a server-set cookie. That is a real trade-off and we would rather say so than pretend otherwise. Every table is protected by row level security, so a session token alone cannot read anything the account is not entitled to.
Changes, and contact
We may update this page. If a change materially affects your rights we will note the change and its date at the top rather than changing it silently.
Questions, corrections, or a data deletion request: isaaclum1209@gmail.com