Privacy Policy
How MobileHub collects, uses, shares, and protects your personal data — in accordance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA)
Last updated: May 10, 2026
1. Data Controller
The data controller for the personal data described in this notice is:
- Name: MobileHub developer (operating as a sole proprietor)
- Email: support@ajsoftwaredev.com
Our Data Protection contact can be reached at support@ajsoftwaredev.com — please use the subject line "Data Subject Request" so we can route the message faster.
2. Data We Collect
We collect only what is necessary to operate the Service. Data falls into four categories:
- Account information — name, email, phone number, password (stored as a bcrypt hash with 12 rounds), shop name, branches.
- Usage data — data you enter into the system: products, customers, repair jobs, sales transactions, plus access audit logs.
- Payment data — uploaded transfer slips, amount, timestamp. We do not store credit card or ATM information.
- Technical data — IP address, user agent (browser/OS), access timestamps, used for security and abuse detection.
3. Legal Basis for Processing
We process your data under the following legal bases (PDPA §24):
| Legal Basis | Where it applies |
|---|---|
Contract | Delivering the Service you signed up for — account info, usage, transactions. |
Legitimate Interest | Security, fraud prevention, service improvement — IP, browser logs, audit trails. |
Consent | Web Push Notifications and marketing emails (opt-in only). |
Legal Obligation | Retention of receipts and tax records for 5 years per the Revenue Code. |
4. How We Use Your Data
- Provide the mobile-shop management service you signed up for.
- Authenticate your identity and manage your account.
- Send transactional email/SMS/push notifications related to your usage.
- Process payments and issue receipts.
- Detect and prevent fraud, abuse, and intrusion.
- Improve service quality and develop new features (without identifying individuals).
- Comply with court orders or requests from authorised government agencies.
5. Sharing With Third Parties
We use a small set of third-party providers necessary to deliver the Service. We share only the minimum data required, under each provider's own privacy policy:
| Provider | Purpose | Data shared |
|---|---|---|
| Hostinger SMTP | Email delivery (OTP, receipts, alerts) | Recipient email + message body |
| FCM / Mozilla Autopush / Apple APNs | Web Push delivery | Browser endpoint + notification payload |
| Banks & PromptPay | Payment verification | Transfer reference + amount (from slip OCR) |
| OCR providers (EasySlip / SlipOK / Thunder) | Automated slip verification (opt-in) | Uploaded slip image |
6. Cross-Border Data Transfers
Our primary servers are located in Thailand, but a few third-party services run abroad:
- Google FCM (Web Push for Chrome/Edge/Android) — Google Cloud, United States
- Mozilla Autopush (Firefox) — United States
- Apple APNs (Safari) — United States
Per PDPA §28, cross-border transfers must have adequate protection. These providers comply with international standards (GDPR-aligned), and the data shared is limited to endpoint URLs and notification payloads — no other personal data is transferred.
7. Cookies & Tracking Technologies
We use only the minimum technologies needed for the system to function:
- JWT (auth token) — stored in localStorage, expires after 24 hours for tenants and 12 hours for admins.
- localStorage / sessionStorage — for user preferences (selected branch, sidebar collapsed state, etc.).
- Service Worker — for Web Push Notifications (opt-in).
- HTTP cookies — strictly necessary cookies only (sessions).
We do not use Google Analytics, Facebook Pixel, or any cross-site tracking technology.
8. Data Retention
- Active accounts — retained for the lifetime of the account.
- Cancelled / expired accounts — retained for 30 additional days to allow reactivation, then permanently deleted.
- Sales / repair / purchase records — retained for 5 years per the Thai Revenue Code.
- Audit logs — retained for 1 year for security purposes.
- Push subscriptions — retained while the device is active; auto-cleaned when unsubscribed.
- Encrypted backups — taken daily, retained for 30 days, then automatically deleted.
9. Your Rights as a Data Subject
Under PDPA §30-§39, you have the following rights:
- Right of accessrequest a copy of the personal data we hold about you.
- Right to rectificationrequest correction of inaccurate or outdated data.
- Right to erasurerequest deletion of your personal data (except data we must keep by law).
- Right to restrict processingrequest that processing be paused — for example, while accuracy is verified.
- Right to objectobject to processing based on "legitimate interest".
- Right to data portabilityreceive your data in a machine-readable format (e.g., JSON / CSV).
- Right to withdraw consentwithdraw consent (e.g., turn off Push Notifications) at any time.
- Right to lodge a complaintfile a complaint with the Personal Data Protection Committee (PDPC) if you believe processing is unlawful.
To exercise any right, send a request to support@ajsoftwaredev.com with proof of identity. We will respond within 30 days as required by PDPA.
10. Account & Data Deletion
You may request deletion of your account and all data at any time by contacting support@ajsoftwaredev.com and verifying your identity through the registered email. We will complete the deletion within 7 business days.
Exception: data we are required to retain by law (e.g., tax receipts) will be kept for the legally mandated period, but will not be used for any other purpose.
11. Security
We use industry-standard security measures:
- HTTPS + HSTS encryption for all communication.
- Passwords stored as bcrypt hashes (12 rounds).
- JWT signed with separate secrets for tenant and admin tokens.
- Multi-tenant isolation enforced at the database query layer (every query is scoped by tenantId).
- Rate limiting and IP-based brute-force protection.
- Daily encrypted backups with restore capability.
- OTP codes generated with crypto.randomInt + SHA-256 hashing.
- Full security headers — CSP, HSTS, X-Frame-Options, etc.
12. Filing a Complaint
If you believe your data is being processed improperly, you may:
- Contact us directly at support@ajsoftwaredev.com for resolution — we will respond within 30 days.
- Or lodge a complaint with the Personal Data Protection Committee (PDPC), Office of the Personal Data Protection Committee: www.pdpc.or.th
13. Changes to This Policy
We may update this policy from time to time as laws, technology, or our service evolves. Material changes will be announced at least 30 days in advance via email or in-app notice. The last updated date is shown at the top of this page.
14. Contact Us
For questions about this policy, please email support@ajsoftwaredev.com. A full list of contact channels is available in the site footer.
For questions about this document, please contact us at support@ajsoftwaredev.com