Privacy Policy
Last updated: 12 July 2026
This policy explains how BoxBak (“we”, “us”) collects, uses, discloses, and protects personal data under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA). It covers visitors to our website, store owners and staff who use the system, and a store’s customers who order via QR. This English version is provided for convenience — the Thai version prevails if the two conflict.
1. Our role for each kind of data
- Account data of the person who signs up (e.g. the owner’s email and name) — we act as the data controller.
- Data a store records in the system (staff records, time clock, payroll, sales, customer orders, etc.) — the store is the controller and we act as a data processor on the store’s instructions given through its use of the system. Requests concerning this data should be made to the store you deal with first; we support the store in fulfilling them.
2. Data we collect
Account and authentication data
- Email, name, and username of owners and staff.
- Passwords and PINs, always stored as one-way hashes — we cannot read the original values.
- Identifiers of devices bound to a store for front-of-house sign-in, and a LINE user ID when a user chooses to link their account for OTP delivery.
System usage data
- Sales, orders, stock, costs, and documents the store records.
- Clock-in/out times, shift schedules, and compensation data the store records.
- System audit logs of key financial, stock, and permission actions, designed to be tamper-evident for transparency and review.
Store customers (QR ordering)
- The items ordered and the table they were ordered from. Customers are not required to register or identify themselves.
Payment data
- Payment status from payment providers (e.g. PromptPay confirmation). We do not store full card numbers or bank account details of payers.
3. Cookies we use
- Session cookie — strictly necessary for secure sign-in; digitally signed against tampering and expires automatically.
- Store device cookie — strictly necessary to recognize devices the store has approved, so staff can sign in at the counter safely and conveniently.
- We use no advertising cookies and no cross-site tracking cookies.
4. Purposes and legal bases
- Providing the contracted service — creating accounts, signing in, recording and displaying the store’s data (contract).
- Security, fraud prevention, and investigating anomalies (legitimate interests).
- Complying with law, such as keeping accounting and tax records (legal obligation).
- Sending essential account and service emails — marketing communications only with your consent (consent).
5. Disclosure to third parties
We do not sell personal data. We disclose it only as needed to run the service, to sub-processors under data protection agreements: cloud infrastructure and database providers, our transactional email provider, the LINE platform (when a user links their account), and payment providers — and where required by law or a lawful government order. Some providers are located abroad; we select providers with data protection standards adequate under the PDPA.
6. Retention
- Account and store data — for as long as the account remains active.
- After cancellation — up to 90 days to allow recovery, except data we must keep by law (e.g. accounting and tax records), which is kept for the statutory period; it is then deleted or anonymized.
- System logs — kept as long as needed for security and auditing.
7. Security measures
- All connections are encrypted over HTTPS.
- Passwords and PINs are stored only as hashes.
- Each store’s data is isolated at the database level (row-level security) — one store cannot access another’s data.
- Access within a store is role-based, and key actions carry an audit log that can be reviewed after the fact.
8. Your rights under the PDPA
You may request access to and a copy of your data, correction, deletion or destruction, restriction of use, objection to processing, data portability, and withdrawal of consent you have given, by contacting us below. We will respond within the statutory period, and you may lodge a complaint with Thailand’s Personal Data Protection Committee (PDPC) if you believe processing violates the law. For data controlled by a store (such as staff records or customer orders), please direct your request to the store.
9. Children’s data
The service is designed for business operators. We do not intend to collect minors’ data; if we find such data collected without valid consent, we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. For material changes we will give reasonable advance notice through the system or by email. The latest update date is shown at the top of this page.
11. Contact
Data controller: BoxBak — for questions or data subject requests, contact beronzemulti@gmail.com