Back home
Privacy policy

Privacy Policy

This policy explains what ecenoww collects, uses, and protects when you register or open a store.

Last updated: September 2, 2026

1. Roles and scope

  • ecenoww acts as controller for platform accounts, subscriptions, security, official communications, and platform operations.
  • For customer data a merchant collects to sell and deliver its products, the merchant may be a separate controller and ecenoww processes data on its instructions as needed to provide the service.
  • Customers should also read the merchant's privacy notice because the merchant independently determines some uses of customer data.

2. Data collected and sources

  • Account and identity data includes email, username, phone, verification status, roles, team permissions, and official communications.
  • Store and usage data includes store identity, domain, content, catalog, stock, orders, LINE/Discord settings, activity logs, IP address, device, and technical events.
  • Transaction data includes plans, invoices, amounts, credits, payouts, receiver details, slip URLs or QR data, and verification results.
  • Data comes from users, merchants, team members, customers, service activity, and connected providers authorized by the user.

3. Purposes and legal bases

  • We process data to perform contracts and provide accounts, stores, orders, digital delivery, plans, credits, payment verification, payouts, and official communications.
  • We rely on legitimate interests where appropriate for security, fraud prevention, incident investigation, audit logging, service improvement, and protecting users' rights, while considering the impact on individuals.
  • We also process data to comply with law, government orders, tax, accounting, and disputes, or with consent where consent is legally required and may be withdrawn.

4. Sharing, processors, and international transfers

  • We share only necessary data with relevant merchants and providers for hosting, files, email, notifications, LINE, Discord, payments, slip verification, professional advice, and other contracted operations.
  • We do not sell personal data. We may disclose it to regulators, courts, or relevant parties when supported by law or needed to protect rights and safety.
  • Some providers may process data outside Thailand; ecenoww applies appropriate measures required for international transfers.

5. Connected mailboxes and provider codes

  • Only a store owner may connect Gmail or a personal Microsoft Outlook/Hotmail account with read-only permission. The owner may disconnect it, after which authorization is revoked where the provider supports revocation and stored credentials are cryptographically destroyed through the security cleanup process.
  • During an order-based or owner-enabled Public OTP request, the service searches messages received within each provider code's actual 5–15 minute lifetime and waits up to 30 seconds for new mail. Content is read only when sender, subject, template, DKIM, DMARC, and Microsoft compauth checks match. Attachments and remote resources are never fetched.
  • Order-based OTP is transferred only to an authenticated customer with a completed, still-eligible order. Public OTP lets an unauthenticated visitor enter the exact address of a connected, OTP-enabled mailbox and search without purchasing. Gmail dot or plus aliases are not canonicalized, and mailbox addresses are never listed publicly.
  • For Public OTP, only purpose-bound HMACs of the email and IP are retained for rate limiting; raw email and IP values are not stored. Unknown email, duplicate request, quota exhaustion, busy mailbox, and unavailable account outcomes use the same public no-result response. A code is revealed once and held only in the current tab's memory until expiry.
  • We do not retain message subjects, email bodies, or raw MIME. Codes are KMS-envelope-encrypted and ciphertext is destroyed immediately after reveal, expiry, cancellation, or Public OTP shutdown. Rate-limit HMACs are cleared after 24 hours plus a safety margin, aggregate attempt records are kept for 30 days, and expired sessions are purged automatically.
  • Public OTP uses Cloudflare Turnstile, rate limits, and a necessary 30-minute session cookie. The owner can disable it at any time, but a code already viewed or copied to a visitor's device cannot be recalled.
  • Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
  • Microsoft Graph data is used only to find and transfer a one-time code for the consented purpose and is handled under the applicable Microsoft terms.

6. Cookies, logs, and communications

  • The service uses cookies necessary for login, language, theme, security, and sessions, and uses logs to diagnose failures and prevent attacks.
  • We may send OTPs, verification messages, invoices, transaction alerts, security notices, and essential service communications. Optional marketing can be disabled where offered.

7. Retention and deletion

  • Data is retained while an account or store remains active and afterwards as needed for transactions, tax, accounting, backups, security, disputes, and applicable limitation periods.
  • When no longer needed, data is deleted, destroyed, or de-identified. Closing an account may not immediately remove legally required records or data independently controlled by a merchant.

8. Security and data incidents

  • We use access controls, tenant separation, encryption in transit, activity logging, backups, and organizational controls appropriate to the risk, but no online system can guarantee absolute security.
  • If a personal-data incident occurs, we will assess and contain it and notify authorities or affected individuals as required by law. Users must promptly report suspicious account or data access.

9. Data subject rights

  • Subject to law, individuals may request access, copies, correction, portability, erasure, restriction or objection, withdraw consent, and complain to Thailand's Personal Data Protection Committee.
  • We verify identity and may limit or refuse a request where law permits, including to protect others, preserve legal claims, or retain required records, and will provide reasons where possible.

10. Minors, changes, and contact

  • Minors should use the service with lawful guardian consent and should not submit unnecessary personal data.
  • Material policy changes will be dated and notified through the website, service, or contact channels.
  • Privacy questions and rights requests may be submitted through official channels on the ecenoww website with enough information to verify identity and locate the relevant records.