Back to home

Privacy Policy

How MobileHub collects, uses, shares, and protects your personal data — in accordance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA)

Last updated: May 10, 2026

1. Data Controller

The data controller for the personal data described in this notice is:

Our Data Protection contact can be reached at support@ajsoftwaredev.com — please use the subject line "Data Subject Request" so we can route the message faster.

2. Data We Collect

We collect only what is necessary to operate the Service. Data falls into four categories:

  • Account information — name, email, phone number, password (stored as a bcrypt hash with 12 rounds), shop name, branches.
  • Usage data — data you enter into the system: products, customers, repair jobs, sales transactions, plus access audit logs.
  • Payment data — uploaded transfer slips, amount, timestamp. We do not store credit card or ATM information.
  • Technical data — IP address, user agent (browser/OS), access timestamps, used for security and abuse detection.

3. Legal Basis for Processing

We process your data under the following legal bases (PDPA §24):

Legal BasisWhere it applies
Contract
Delivering the Service you signed up for — account info, usage, transactions.
Legitimate Interest
Security, fraud prevention, service improvement — IP, browser logs, audit trails.
Consent
Web Push Notifications and marketing emails (opt-in only).
Legal Obligation
Retention of receipts and tax records for 5 years per the Revenue Code.

4. How We Use Your Data

  • Provide the mobile-shop management service you signed up for.
  • Authenticate your identity and manage your account.
  • Send transactional email/SMS/push notifications related to your usage.
  • Process payments and issue receipts.
  • Detect and prevent fraud, abuse, and intrusion.
  • Improve service quality and develop new features (without identifying individuals).
  • Comply with court orders or requests from authorised government agencies.

5. Sharing With Third Parties

We use a small set of third-party providers necessary to deliver the Service. We share only the minimum data required, under each provider's own privacy policy:

ProviderPurposeData shared
Hostinger SMTPEmail delivery (OTP, receipts, alerts)Recipient email + message body
FCM / Mozilla Autopush / Apple APNsWeb Push deliveryBrowser endpoint + notification payload
Banks & PromptPayPayment verificationTransfer reference + amount (from slip OCR)
OCR providers (EasySlip / SlipOK / Thunder)Automated slip verification (opt-in)Uploaded slip image

6. Cross-Border Data Transfers

Our primary servers are located in Thailand, but a few third-party services run abroad:

  • Google FCM (Web Push for Chrome/Edge/Android) — Google Cloud, United States
  • Mozilla Autopush (Firefox) — United States
  • Apple APNs (Safari) — United States

Per PDPA §28, cross-border transfers must have adequate protection. These providers comply with international standards (GDPR-aligned), and the data shared is limited to endpoint URLs and notification payloads — no other personal data is transferred.

7. Cookies & Tracking Technologies

We use only the minimum technologies needed for the system to function:

  • JWT (auth token) — stored in localStorage, expires after 24 hours for tenants and 12 hours for admins.
  • localStorage / sessionStorage — for user preferences (selected branch, sidebar collapsed state, etc.).
  • Service Worker — for Web Push Notifications (opt-in).
  • HTTP cookies — strictly necessary cookies only (sessions).

We do not use Google Analytics, Facebook Pixel, or any cross-site tracking technology.

8. Data Retention

  • Active accounts — retained for the lifetime of the account.
  • Cancelled / expired accounts — retained for 30 additional days to allow reactivation, then permanently deleted.
  • Sales / repair / purchase records — retained for 5 years per the Thai Revenue Code.
  • Audit logs — retained for 1 year for security purposes.
  • Push subscriptions — retained while the device is active; auto-cleaned when unsubscribed.
  • Encrypted backups — taken daily, retained for 30 days, then automatically deleted.

9. Your Rights as a Data Subject

Under PDPA §30-§39, you have the following rights:

  • Right of access
    request a copy of the personal data we hold about you.
  • Right to rectification
    request correction of inaccurate or outdated data.
  • Right to erasure
    request deletion of your personal data (except data we must keep by law).
  • Right to restrict processing
    request that processing be paused — for example, while accuracy is verified.
  • Right to object
    object to processing based on "legitimate interest".
  • Right to data portability
    receive your data in a machine-readable format (e.g., JSON / CSV).
  • Right to withdraw consent
    withdraw consent (e.g., turn off Push Notifications) at any time.
  • Right to lodge a complaint
    file a complaint with the Personal Data Protection Committee (PDPC) if you believe processing is unlawful.

To exercise any right, send a request to support@ajsoftwaredev.com with proof of identity. We will respond within 30 days as required by PDPA.

10. Account & Data Deletion

You may request deletion of your account and all data at any time by contacting support@ajsoftwaredev.com and verifying your identity through the registered email. We will complete the deletion within 7 business days.

Exception: data we are required to retain by law (e.g., tax receipts) will be kept for the legally mandated period, but will not be used for any other purpose.

11. Security

We use industry-standard security measures:

  • HTTPS + HSTS encryption for all communication.
  • Passwords stored as bcrypt hashes (12 rounds).
  • JWT signed with separate secrets for tenant and admin tokens.
  • Multi-tenant isolation enforced at the database query layer (every query is scoped by tenantId).
  • Rate limiting and IP-based brute-force protection.
  • Daily encrypted backups with restore capability.
  • OTP codes generated with crypto.randomInt + SHA-256 hashing.
  • Full security headers — CSP, HSTS, X-Frame-Options, etc.

12. Filing a Complaint

If you believe your data is being processed improperly, you may:

  • Contact us directly at support@ajsoftwaredev.com for resolution — we will respond within 30 days.
  • Or lodge a complaint with the Personal Data Protection Committee (PDPC), Office of the Personal Data Protection Committee: www.pdpc.or.th

13. Changes to This Policy

We may update this policy from time to time as laws, technology, or our service evolves. Material changes will be announced at least 30 days in advance via email or in-app notice. The last updated date is shown at the top of this page.

14. Contact Us

For questions about this policy, please email support@ajsoftwaredev.com. A full list of contact channels is available in the site footer.

For questions about this document, please contact us at support@ajsoftwaredev.com