← กลับหน้าแรก← Back to Home

นโยบายความเป็นส่วนตัว

ปรับปรุงล่าสุด: 1 กันยายน 2569 · มีผลบังคับใช้: 1 กันยายน 2569 · สอดคล้องตาม พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)
เอกสารฉบับนี้เป็นโครงร่างเบื้องต้น ควรให้ที่ปรึกษากฎหมายด้าน PDPA ตรวจสอบก่อนใช้งานจริง และเติมข้อมูลในส่วน [...] ให้ครบถ้วน

โดยที่พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 ("กฎหมาย") มีวัตถุประสงค์ในการคุ้มครองสิทธิส่วนบุคคลของเจ้าของข้อมูลส่วนบุคคล การเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลย่อมต้องเป็นไปตามเงื่อนไขและวิธีการที่กฎหมายกำหนด เพื่อให้การประมวลผลข้อมูลส่วนบุคคลผ่านการดำเนินกิจกรรมของ [รอจดบริษัท — ชื่อนิติบุคคล] ("บริษัทฯ", "เรา") ผู้ให้บริการแพลตฟอร์ม Maibit เป็นไปตามกฎหมาย บริษัทฯ จึงจัดทำนโยบายความเป็นส่วนตัวฉบับนี้ ("นโยบายฯ") เพื่อให้ท่านในฐานะเจ้าของข้อมูลส่วนบุคคลรับทราบและตระหนักถึงความสำคัญในการคุ้มครองข้อมูลส่วนบุคคลของท่าน

1. นิยาม

"ข้อมูลส่วนบุคคล" หมายถึง ข้อมูลของบุคคลธรรมดาซึ่งทำให้สามารถระบุตัวบุคคลนั้นได้ไม่ว่าทางตรงหรือทางอ้อม เช่น ชื่อ-นามสกุล อายุ เพศ วันเดือนปีเกิด เลขบัตรประจำตัวประชาชน เบอร์โทรศัพท์ อีเมล ภาพถ่าย แต่ไม่รวมถึงข้อมูลของผู้ถึงแก่กรรม

"ข้อมูลส่วนบุคคลที่มีความอ่อนไหว" หมายถึง ข้อมูลส่วนบุคคลเกี่ยวกับเชื้อชาติ เผ่าพันธุ์ ความคิดเห็นทางการเมือง ความเชื่อ ศาสนา พฤติกรรมทางเพศ ประวัติอาชญากรรม ข้อมูลสุขภาพ ความพิการ ข้อมูลพันธุกรรม ข้อมูลชีวภาพ หรือข้อมูลอื่นใดตามที่กฎหมายกำหนด (อาทิ ศาสนาที่อาจปรากฏในสำเนาบัตรประชาชน)

"การประมวลผล" หมายถึง การเก็บรวบรวม ใช้ เปิดเผย หรือการกระทำใด ๆ ต่อข้อมูลส่วนบุคคล รวมถึงการส่งต่อ โอน ทำลาย หรือลบ

"เจ้าของข้อมูลส่วนบุคคล" หรือ "ท่าน" หมายถึง บุคคลธรรมดาที่บริษัทฯ ประมวลผลข้อมูลส่วนบุคคลตามนโยบายฯ นี้

2. การเก็บรวบรวมข้อมูลส่วนบุคคล

บริษัทฯ จะเก็บรวบรวมข้อมูลส่วนบุคคลของท่านตามวัตถุประสงค์และอำนาจแห่งกฎหมายเท่านั้น โดยอาจเก็บผ่านช่องทางดังนี้:

  • การสมัครสมาชิกผ่านอีเมลหรือเบอร์โทรศัพท์
  • การสมัครหรือเข้าสู่ระบบผ่านบัญชี Google หรือ Facebook
  • การยืนยันตัวตน (KYC) ผ่านการอัปโหลดเอกสารราชการ
  • ข้อมูลที่ท่านกรอกในระบบพูดคุย ประกาศขาย หรือออเดอร์
  • ข้อมูลทางเทคนิคที่เก็บอัตโนมัติเมื่อท่านใช้งานแพลตฟอร์ม

ในกรณีที่มีการเก็บข้อมูลส่วนบุคคลจากแหล่งอื่น บริษัทฯ จะแจ้งให้ท่านทราบและดำเนินการตามกฎหมายภายใน 30 วันนับแต่วันที่เก็บรวบรวม

3. ประเภทของข้อมูลส่วนบุคคล

  • ข้อมูลประจำตัว: ภาพถ่าย ชื่อ-นามสกุล อายุ วันเดือนปีเกิด
  • ข้อมูลการติดต่อ: ที่อยู่ เบอร์โทรศัพท์ อีเมล
  • ข้อมูลบัญชี: บัญชีผู้ใช้งาน ประวัติการใช้งาน รีวิว
  • หลักฐานยืนยันตัวตน: บัตรประจำตัวประชาชน เอกสารราชการสำหรับ KYC
  • ข้อมูลธุรกรรมและการเงิน: ประวัติการซื้อขาย การเติมเงิน การถอนเงิน ข้อมูลบัญชีธนาคารสำหรับการถอน
  • ข้อมูลทางเทคนิค: IP Address, Cookie ID, ประวัติการใช้งาน (Activity Log)
  • ข้อมูลอื่น ๆ: ข้อความในระบบพูดคุย หลักฐานข้อพิพาท ข้อเสนอแนะ
บริษัทฯ ไม่ประสงค์เก็บข้อมูลส่วนบุคคลที่มีความอ่อนไหว หากปรากฏข้อมูลดังกล่าวในเอกสาร KYC (เช่น ศาสนาในบัตรประชาชน) ท่านสามารถปิดบังก่อนอัปโหลดได้ และบริษัทฯ จะไม่นำข้อมูลส่วนนั้นไปใช้

4. วัตถุประสงค์ของการประมวลผล

  • เพื่อสร้างและจัดการบัญชีผู้ใช้งาน
  • เพื่อดำเนินการซื้อขาย ชำระเงิน และระบบพักเงิน (escrow)
  • เพื่อการยืนยันตัวตน (KYC) และการถอนเงิน
  • เพื่อระงับข้อพิพาทและให้บริการหลังการขาย
  • เพื่อป้องกันการทุจริต ฟอกเงิน และการใช้งานที่ฝ่าฝืนเงื่อนไข
  • เพื่อควบคุมไม่ให้มีการแลกข้อมูลติดต่อหรือทำธุรกรรมนอกแพลตฟอร์ม
  • เพื่อปฏิบัติตามข้อตกลงการใช้งานและกฎหมาย
  • เพื่อวิเคราะห์และปรับปรุงประสิทธิภาพของแพลตฟอร์ม
  • เพื่อการตลาดและการสื่อสาร (เมื่อได้รับความยินยอม)

5. ฐานทางกฎหมายในการประมวลผล

บริษัทฯ ประมวลผลข้อมูลส่วนบุคคลของท่านบนฐานทางกฎหมายดังนี้:

  • ฐานสัญญา: เพื่อปฏิบัติตามสัญญาการใช้บริการ เช่น การสร้างบัญชี การดำเนินธุรกรรม
  • ฐานประโยชน์โดยชอบด้วยกฎหมาย: เช่น การป้องกันการทุจริต การรักษาความปลอดภัย การปรับปรุงบริการ
  • ฐานการปฏิบัติตามกฎหมาย: เช่น การยืนยันตัวตน การเก็บข้อมูลธุรกรรมตามกฎหมาย
  • ฐานความยินยอม: เช่น การตลาด การส่งข่าวสารโปรโมชัน คุกกี้เพื่อการวิเคราะห์

7. การประมวลผลเพื่อการตลาด

บริษัทฯ อาจประมวลผลข้อมูลส่วนบุคคลเพื่อการโฆษณาและการตลาดผ่านช่องทางต่าง ๆ เช่น Google, Facebook, LINE หรือเครื่องมือวิเคราะห์อื่น ๆ โดยจะดำเนินการเมื่อได้รับความยินยอม

หากท่านไม่ต้องการรับข่าวสารการตลาด ท่านสามารถยกเลิกได้ทุกเมื่อผ่านลิงก์ "ยกเลิกการรับข่าวสาร" ในอีเมล หรือผ่านการตั้งค่าบัญชี การถอนความยินยอมจะไม่กระทบต่อการประมวลผลที่ได้ดำเนินการไปแล้วโดยชอบด้วยกฎหมาย

8. การเปิดเผยและการส่งต่อข้อมูล

บริษัทฯ จะเปิดเผยข้อมูลส่วนบุคคลของท่านตามวัตถุประสงค์ที่เก็บรวบรวมหรือตามอำนาจแห่งกฎหมายเท่านั้น โดยอาจเปิดเผยให้แก่:

  • ผู้ให้บริการรับชำระเงิน (payment gateway) เพื่อดำเนินการเติมเงินและถอนเงิน
  • ผู้ให้บริการเซิร์ฟเวอร์และโครงสร้างพื้นฐาน (เช่น ผู้ให้บริการคลาวด์)
  • ผู้ให้บริการวิเคราะห์ข้อมูลและการตลาด
  • หน่วยงานของรัฐหรือเมื่อมีคำสั่งตามกฎหมาย
  • คู่กรณีในข้อพิพาท เฉพาะข้อมูลที่จำเป็นต่อการระงับข้อพิพาท

บริษัทฯ จะกำกับดูแลให้ผู้ประมวลผลข้อมูลส่วนบุคคลภายนอกมีมาตรฐานการคุ้มครองข้อมูลตามกฎหมาย ในกรณีที่มีการส่งข้อมูลไปต่างประเทศ บริษัทฯ จะดำเนินการให้เป็นไปตามมาตรฐานที่กฎหมายกำหนด

9. ระยะเวลาในการเก็บรักษาข้อมูล

บริษัทฯ จะเก็บรักษาข้อมูลส่วนบุคคลของท่านตลอดระยะเวลาที่ท่านใช้บริการ และเท่าที่จำเป็นเพื่อให้บรรลุวัตถุประสงค์ที่กำหนด หรือตามที่กฎหมายกำหนด (เช่น ข้อมูลธุรกรรมทางการเงินที่ต้องเก็บตามกฎหมาย)

เมื่อท่านยกเลิกบัญชี บริษัทฯ จะเก็บข้อมูลเท่าที่จำเป็นตามกฎหมาย และจะลบหรือทำลายข้อมูลส่วนที่ไม่จำเป็นออก

10. สิทธิของเจ้าของข้อมูลส่วนบุคคล

ท่านมีสิทธิตามกฎหมายเกี่ยวกับข้อมูลส่วนบุคคลของท่านดังนี้:

สิทธิรายละเอียดระยะเวลาดำเนินการ
เพิกถอนความยินยอมถอนความยินยอมที่ให้ไว้ได้ทุกเมื่อ7 วัน
เข้าถึงและขอสำเนาขอเข้าถึงและรับสำเนาข้อมูลของตนทันที / ตามกำหนด
ขอให้โอนข้อมูลขอให้ส่งหรือโอนข้อมูลไปยังผู้ควบคุมข้อมูลอื่น30 วัน
ขอแก้ไขข้อมูลขอแก้ไขข้อมูลให้ถูกต้องเป็นปัจจุบันทันที / ตามกำหนด
คัดค้านการประมวลผลคัดค้านการประมวลผลในบางกรณี30 วัน
ขอให้ลบหรือทำลายขอให้ลบหรือทำลายข้อมูลในกรณีที่กฎหมายกำหนด30 วัน
ระงับการใช้ข้อมูลขอให้ระงับการใช้ข้อมูลชั่วคราว30 วัน
ร้องเรียนร้องเรียนการประมวลผลที่ไม่ชอบด้วยกฎหมายทันที

ระยะเวลาดำเนินการนับแต่วันที่บริษัทฯ ได้รับเอกสารครบถ้วน ท่านสามารถใช้สิทธิได้ผ่านศูนย์ช่วยเหลือ บริษัทฯ มีสิทธิปฏิเสธคำขอได้หากมีอำนาจประมวลผลตามกฎหมาย โดยจะบันทึกเหตุผลไว้

11. คุกกี้ (Cookies)

บริษัทฯ ใช้คุกกี้และเทคโนโลยีที่คล้ายคลึงกันเพื่อสนับสนุนการทำงานของเว็บไซต์ เพิ่มความปลอดภัย วิเคราะห์การใช้งาน และปรับปรุงประสบการณ์ของท่าน

คุกกี้ที่จำเป็นต่อการทำงานของเว็บไซต์จะถูกใช้โดยไม่ต้องขอความยินยอม ส่วนคุกกี้เพื่อการวิเคราะห์และการตลาดจะถูกใช้เมื่อท่านให้ความยินยอม ท่านสามารถเปลี่ยนแปลงหรือถอนความยินยอมได้ทุกเมื่อผ่านการตั้งค่าคุกกี้

12. การรักษาความมั่นคงปลอดภัย

บริษัทฯ จัดให้มีมาตรการรักษาความมั่นคงปลอดภัยที่เหมาะสม ทั้งด้านการบริหารจัดการ ด้านเทคนิค และด้านกายภาพ เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยข้อมูลโดยมิชอบ ครอบคลุมการรักษาความลับ ความถูกต้องครบถ้วน และสภาพพร้อมใช้งานของข้อมูล

เอกสารยืนยันตัวตน (KYC) จะถูกจัดเก็บในพื้นที่จัดเก็บแบบส่วนตัว (private storage) และเข้าถึงได้เฉพาะเจ้าหน้าที่ที่มีสิทธิเท่านั้น

13. การแจ้งเหตุละเมิดข้อมูล

ในกรณีที่มีเหตุละเมิดข้อมูลส่วนบุคคล บริษัทฯ จะแจ้งให้สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลทราบภายใน 72 ชั่วโมงนับแต่ทราบเหตุเท่าที่สามารถกระทำได้ และหากการละเมิดมีความเสี่ยงสูงต่อสิทธิและเสรีภาพของท่าน บริษัทฯ จะแจ้งให้ท่านทราบพร้อมแนวทางการเยียวยาโดยไม่ชักช้า

14. การแก้ไขเปลี่ยนแปลงนโยบาย

บริษัทฯ อาจแก้ไขเปลี่ยนแปลงนโยบายฯ ได้เป็นครั้งคราว โดยจะประกาศผ่านแพลตฟอร์ม การใช้บริการต่อหลังการเปลี่ยนแปลงถือว่าท่านรับทราบนโยบายฉบับใหม่ นโยบายฉบับนี้มีผลใช้บังคับตั้งแต่วันที่ 1 กันยายน 2569

15. รายละเอียดการติดต่อ

ผู้ควบคุมข้อมูลส่วนบุคคล / เจ้าหน้าที่คุ้มครองข้อมูล (DPO):

ชื่อบริษัทฯ: [รอจดบริษัท — ชื่อนิติบุคคล]
ที่อยู่: [รอจดบริษัท — ที่อยู่จดทะเบียน]
อีเมล: privacy@maibit.com
หรือผ่านศูนย์ช่วยเหลือ

Privacy Policy

Last updated: 1 September 2026 · Effective: 1 September 2026 · In compliance with the Personal Data Protection Act B.E. 2562 (PDPA)
This document is a preliminary draft and should be reviewed by PDPA legal counsel before going live. Please complete all items marked [...]. In case of any discrepancy, the Thai version shall prevail.

The Personal Data Protection Act B.E. 2562 (the "Law") aims to protect the privacy rights of data subjects. The collection, use, or disclosure of personal data must comply with the conditions and methods prescribed by Law. To ensure that the processing of personal data through the activities of [Pending registration — legal entity name] (the "Company", "we"), operator of the Maibit Platform, complies with the Law, the Company has prepared this Privacy Policy (the "Policy") so that you, as a data subject, are informed of and aware of the importance of protecting your personal data.

1. Definitions

"Personal Data" means information about an identifiable natural person, whether directly or indirectly, such as name, age, gender, date of birth, national ID number, phone number, email, or photo, but excluding data of deceased persons.

"Sensitive Personal Data" means personal data concerning race, ethnicity, political opinions, beliefs, religion, sexual behavior, criminal records, health data, disability, genetic data, biometric data, or other data prescribed by Law (e.g. religion that may appear on a copy of a national ID card).

"Processing" means the collection, use, disclosure, or any action taken on personal data, including transfer, destruction, or deletion.

"Data Subject" or "you" means the natural person whose personal data the Company processes under this Policy.

2. Collection of Personal Data

The Company collects your personal data only for lawful purposes and within its legal authority, through channels including:

  • Registration via email or phone number
  • Registration or login via Google or Facebook accounts
  • Identity verification (KYC) through uploaded official documents
  • Information you enter in Chat, Listings, or Orders
  • Technical data collected automatically when you use the Platform

Where personal data is collected from other sources, the Company will notify you and act in accordance with the Law within 30 days of collection.

3. Types of Personal Data

  • Identity data: photo, full name, age, date of birth
  • Contact data: address, phone number, email
  • Account data: user account, usage history, reviews
  • Verification evidence: national ID card, official documents for KYC
  • Transaction & financial data: purchase history, top-ups, withdrawals, bank account details for withdrawal
  • Technical data: IP address, Cookie ID, activity log
  • Other data: messages in Chat, dispute evidence, feedback
The Company does not intend to collect sensitive personal data. If such data appears in KYC documents (e.g. religion on an ID card), you may redact it before uploading, and the Company will not use that portion.

4. Purposes of Processing

  • To create and manage user accounts
  • To carry out sales, payments, and the escrow system
  • For identity verification (KYC) and withdrawals
  • To resolve disputes and provide after-sales service
  • To prevent fraud, money laundering, and breaches of the Terms
  • To prevent the exchange of contact details or off-platform transactions
  • To comply with the Terms of Service and the law
  • To analyze and improve Platform performance
  • For marketing and communications (with consent)

5. Legal Bases for Processing

The Company processes your personal data on the following legal bases:

  • Contract: to perform the service agreement, e.g. creating an account, processing transactions
  • Legitimate interest: e.g. fraud prevention, security, service improvement
  • Legal obligation: e.g. identity verification, retaining transaction records as required by law
  • Consent: e.g. marketing, promotional communications, analytics cookies

7. Processing for Marketing

The Company may process personal data for advertising and marketing through channels such as Google, Facebook, LINE, or other analytics tools, only with your consent.

If you do not wish to receive marketing communications, you may opt out at any time via the "Unsubscribe" link in emails or through account settings. Withdrawal of consent does not affect processing already lawfully carried out.

8. Disclosure & Transfer of Data

The Company discloses your personal data only for the purposes collected or within its legal authority, and may disclose to:

  • Payment gateway providers, to process top-ups and withdrawals
  • Server and infrastructure providers (e.g. cloud providers)
  • Analytics and marketing service providers
  • Government authorities or where required by law
  • Counterparties in a dispute, only data necessary for resolution

The Company ensures third-party processors maintain data protection standards as required by Law. Where data is transferred abroad, the Company will act in accordance with the standards prescribed by Law.

9. Data Retention Period

The Company retains your personal data throughout your use of the service and as long as necessary to fulfill the stated purposes or as required by law (e.g. financial transaction data that must be retained by law).

When you close your account, the Company retains only data necessary under the law and deletes or destroys unnecessary data.

10. Rights of Data Subjects

You have the following legal rights regarding your personal data:

RightDescriptionProcessing time
Withdraw consentWithdraw consent given at any time7 days
Access & copyAccess and obtain a copy of your dataImmediate / as scheduled
Data portabilityRequest transfer of data to another controller30 days
RectificationRequest correction of data to be accurate and currentImmediate / as scheduled
ObjectObject to processing in certain cases30 days
ErasureRequest deletion or destruction where the law permits30 days
Restrict processingRequest temporary suspension of use30 days
ComplainComplain about unlawful processingImmediate

Processing time is counted from when the Company receives complete documents. You may exercise these rights via the Help Center. The Company may refuse a request where it has lawful authority to continue processing, recording the reason.

11. Cookies

The Company uses cookies and similar technologies to support website functionality, enhance security, analyze usage, and improve your experience.

Cookies necessary for website functionality are used without consent; analytics and marketing cookies are used with your consent. You may change or withdraw consent at any time through cookie settings.

12. Security Measures

The Company maintains appropriate security measures — administrative, technical, and physical — to prevent loss, unauthorized access, use, alteration, modification, or disclosure of data, covering confidentiality, integrity, and availability.

KYC verification documents are stored in private storage and accessible only by authorized staff.

13. Data Breach Notification

In the event of a personal data breach, the Company will notify the Personal Data Protection Committee Office within 72 hours of becoming aware, where feasible. Where the breach poses a high risk to your rights and freedoms, the Company will notify you without delay, along with remedial guidance.

14. Changes to This Policy

The Company may amend this Policy from time to time, announced via the Platform. Continued use after changes constitutes acknowledgment of the revised Policy. This Policy takes effect from 1 September 2026.

15. Contact Details

Data Controller / Data Protection Officer (DPO):

Company: [Pending registration — legal entity name]
Address: [Pending registration — registered address]
Email: privacy@maibit.com
or via the Help Center.