Terms & policies

Privacy Policy

Effective:
25 August 2026
Last updated:
25 August 2026

Mydorf takes your privacy seriously. This policy explains how we collect, use, disclose and protect personal data when you visit our website, sign up, or use our services — and what rights you have under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).

1. Data controller

The data controller under this policy is:

  • Legal entity: [TODO: full registered company name, e.g. Datadorf Co., Ltd.]
  • Company registration number: [TODO: 13-digit registration number]
  • Registered address: 555/268 Moo 1, Ban Thum Sub-district, Mueang Khon Kaen District, Khon Kaen 40000, Thailand
  • Office: Regional Science Park Administration Building, Northeast 1 (Khon Kaen), 123 Moo 16, Kalapapruek Road, Nai Mueang Sub-district, Mueang District, Khon Kaen 40002, Thailand
  • Privacy contact email: contact@datadorf.co.th
  • Telephone: 062-916-9989

Data Protection Officer (DPO): [TODO: name and contact channel — if no DPO has been appointed, delete this line and rely on the contact details above.]

2. Scope of this policy

This policy applies to personal data we collect through mydorf.com and the Mydorf web application at app.mydorf.com (Mydorf is delivered as a web application only; there is no mobile app), and our other contact channels such as email, telephone and social media.

Our service connects to third-party platforms including Facebook, Instagram, TikTok and LINE, as well as our logistics provider. Your use of those platforms is governed by their own privacy policies, which are outside our control.

3. Our role: your data vs. your customers' data

Two categories of data must be kept apart, because our legal role differs for each:

  • Merchant (subscriber) data — Mydorf acts as the data controller. This covers your account details, billing information and product usage data.
  • Your end-customers' data — data that flows into the system because you use Mydorf, such as commenter names on a Live stream, comment text, delivery addresses and phone numbers. For this data you are the data controller and Mydorf acts solely as a data processor following your instructions.

As the controller of your end-customers' data, you are responsible for publishing your own store's privacy notice and for having an appropriate legal basis to collect and use that data. Mydorf is only the tool that processes it on your instructions.

4. Personal data we collect

CategoryExamples
Identity and contact dataFull name, store name, email address, phone number, LINE ID / LINE User ID, TikTok account ID
Account dataUsername, hashed password, team role, account settings, sign-in history
Platform connection dataPage/account IDs and access tokens for the Facebook Page, Instagram and LINE OA accounts you connect (for TikTok we store only the account ID, not an access token)
Transaction and order dataLine items, quantities, amounts, order status, uploaded bank transfer slip images (which may show an account name, account number and transaction time), tracking numbers
Your end-customers' dataSocial handles, comment and chat messages, recipient name, delivery address, phone number
Billing dataSubscribed plan, billing cycle, uploaded payment slips and tax invoice details
Technical dataIP address, device and browser type, operating system, activity logs and cookies

Mydorf does not accept card payments and does not use a payment gateway, so we never store credit card numbers or any card data. Payment is made by PromptPay QR transfer followed by uploading the transfer slip, which means the only payment data we hold is the slip image you or your customer uploads — please redact anything unnecessary before uploading. We also do not intend to collect sensitive data under Section 26 (such as race, religion, health or biometric data). If such data reaches us unnecessarily, we delete it once identified.

5. Where the data comes from

  • Directly from you — when you sign up, fill in the trial form, contact support, or use the product.
  • Automatically from your use of the service — activity logs, cookies and device data.
  • From third-party platforms — when you authorise Mydorf to connect to your social pages or accounts, we receive only what the permission scope you granted covers.
  • From referrals and business partners — for example when a teammate or partner invites you into the product.

6. Purposes and legal bases

PurposeLegal basis (PDPA)
Creating and maintaining your account, delivering your subscribed plan, and providing supportContract (Section 24(3))
Billing, issuing receipts and tax invoices, and keeping accountsContract and legal obligation (Section 24(6))
Keeping the platform secure and detecting fraud or abuseLegitimate interest (Section 24(5))
Analysing and improving the service, building new features, and producing anonymised statisticsLegitimate interest
Sending news, promotions and marketing by email or other channelsConsent (Section 19) — withdrawable at any time
Analytics and marketing cookiesConsent
Complying with lawful government requests, legal process, and tax record-keepingLegal obligation

If we ever need to use your data for a purpose not listed here, we will notify you and obtain consent first, unless the law provides otherwise.

7. Cookies and tracking technologies

Our website uses cookies to make the product work correctly, remember your preferences, and understand how the site is used overall.

  • Strictly necessary cookies — required for sign-in and security; these cannot be disabled.
  • Preference cookies — your chosen language and colour theme, stored in your browser.
  • Analytics cookies — help us see which pages are used and how often [TODO: name the tool actually used, e.g. Google Analytics 4].
  • Marketing cookies — used to measure advertising and show relevant content [TODO: e.g. Meta Pixel, if actually in use].

You can manage or delete cookies in your browser settings. Disabling some categories may cause parts of the site to stop working properly.

8. Disclosure to third parties

We do not sell your personal data. We disclose it only as necessary, to the following recipients:

  • Infrastructure and cloud providers that store and process the data [TODO: name providers, e.g. AWS / Google Cloud]
  • The social platforms you connect — Meta (Facebook Pages and Instagram), LINE OA and TikTok — within the permission scope you granted
  • The bank that holds our receiving account, which sees transfer details through PromptPay in the ordinary course
  • Rocket8, our logistics provider, which receives the recipient name, delivery address and phone number needed to ship the orders you create
  • Email, notification and product analytics providers
  • Professional advisers, auditors and government authorities, where required by law or lawful order

We put Data Processing Agreements in place with our processors, requiring them to use the data only on our instructions and to protect it appropriately.

9. International data transfers

Some of our providers operate servers or operations outside Thailand [TODO: name the countries/regions actually used, e.g. Singapore]. Where that happens, we ensure appropriate safeguards under Sections 28 and 29 of the PDPA — for example standard contractual clauses, or transfers to jurisdictions with an adequate level of protection.

10. How long we keep data

We keep personal data only as long as needed for the purposes described, or as required by law.

CategoryRetention period
Account and usage dataFor as long as the account is active, plus [TODO: e.g. 90 days] after closure
Order data and end-customer dataAs configured by you in the product, or until you delete it
Accounting and tax records such as receipts and tax invoicesAt least 5 years, per the Thai Revenue Code
Security and access logsAt least 90 days, per the Computer-Related Crime Act

Once those periods lapse, we delete, destroy or anonymise the data.

11. Security measures

  • Data encrypted in transit with TLS; passwords stored using one-way hashing
  • Access restricted on a need-to-know basis
  • Third-party access tokens stored encrypted and revoked immediately when you disconnect an integration
  • Regular backups, with access logs kept for auditing
  • Periodic review of access rights and security controls

If a personal data breach occurs that poses a risk to individuals' rights and freedoms, we will notify the Personal Data Protection Committee within 72 hours of becoming aware of it, and notify affected data subjects where the risk is high.

12. Your rights as a data subject

Under the PDPA you have the right to:

  • Access your personal data and request a copy of it
  • Request portability of your data to another controller in a machine-readable format
  • Object to the collection, use or disclosure of your personal data
  • Request erasure, destruction or anonymisation of your data
  • Request suspension of the use of your personal data
  • Request rectification so your data is accurate, current and not misleading
  • Withdraw consent previously given, without affecting the lawfulness of processing before withdrawal
  • Lodge a complaint with the Personal Data Protection Committee

To exercise a right, contact us using the details under “Contact us and complaints”. We will respond within 30 days of receiving your request. We may ask you to verify your identity first, and we may refuse a request where the law allows — in which case we will explain why.

If you are an end-customer who bought from a store using Mydorf, please contact that store directly to exercise your rights: the store is your data controller. We will assist the store in fulfilling your request.

13. Minors

Our service is intended for business operators who have reached the age of majority. We do not knowingly collect data from minors under 20 without the consent of a parent or guardian. If we discover we hold such data without valid consent, we will delete it promptly.

14. Changes to this policy

We may update this policy from time to time to reflect changes in our service or in the law. The date at the top of this page always shows the latest revision. For material changes, we will give advance notice by email or an in-product notification.

15. Contact us and complaints

For questions, to exercise your rights, or to raise a data protection complaint, contact us at:

  • Email: contact@datadorf.co.th
  • Telephone: 062-916-9989
  • Address: Regional Science Park Administration Building, Northeast 1 (Khon Kaen), 123 Moo 16, Kalapapruek Road, Nai Mueang Sub-district, Mueang District, Khon Kaen 40002, Thailand

If you believe we are not complying with data protection law, you also have the right to complain directly to Thailand's Personal Data Protection Committee (PDPC).

Back to top