This policy explains how Digiwava Co., Ltd. collects, uses, discloses, and retains personal data under
Thailand's Personal Data Protection Act (PDPA). It applies to anyone who accesses Digiwava. The full policy
follows; here is the short version:
We collect only what we need to run the marketplace:
Account Information
When you create an account, you provide a username (your public identifier on the platform). For sign-in, you
can use an email address (kept private) with a password or a one-time sign-in link we email to you, a
third-party provider such as Google, or a Web3 wallet (Ethereum or Solana). When you use a third-party
provider, that provider shares basic account information with us, which is stored as part of your sign-in
record; the exact details depend on the provider. When you sign in with a Web3 wallet, your public wallet
address is stored and serves as your account identity; an account created this way has no email address unless
you later add one in your settings. We use your email address, where one is present, to create and identify
your account, and do not use the rest. You can optionally add profile enhancements like an avatar, about
section, or shop name to personalize your presence on the platform.
Transaction Information
For buyers, we maintain a private record of your purchases, including seller product purchases and
platform-direct purchases such as credit packages, together with what you bought, when, the transaction
status, download history where applicable, and your current wishlist items. We also record when an
authenticated buyer adds or removes a wishlist item and when a saved item is purchased, as described in
Section 4.
For sellers, we track your digital product listings, sales metrics, and performance data to help you
understand your business.
Reviews you write become public and associated with your username.
Payment Information
We do not receive or store full card numbers, security codes, or payment credentials. When you make a
purchase, you enter those details into Stripe's secure form embedded on our checkout page. They go directly to
Stripe's PCI-compliant servers. Stripe provides us with limited transaction and card metadata, such as the
transaction ID, payment status, payment method type, and the card's last four digits where applicable.
For sellers, Stripe handles all identity verification, tax documentation, and banking details directly on
their platform. We store only your Stripe account ID. Payouts flow directly from Stripe to your bank account.
We do not hold your funds, but we may request Stripe to pause payouts to your account if we detect suspicious
activity or to comply with Stripe's requirements (see
Terms of Use, Section 4.6).
Billing and Invoice Information
The platform generates receipts and tax invoices for purchases. What we collect depends on your role:
Sellers who list paid products provide business details for their receipts: a business name, a tax
identification number (TIN), and optionally a phone number. VAT-registered sellers also provide a business
address and branch code. These details are stored separately from your public profile and appear only on the
receipts and tax invoices issued to your buyers.
Buyers never need to provide billing details to purchase. If you want a full tax invoice, you provide the
name to show on it, a TIN, a billing address, and optional branch details, either at checkout or, for eligible
purchases, later from your Purchases page, where you can also correct an invoice that was issued
with wrong details. Full tax invoices are available for purchases from VAT-registered sellers. You can save
these details in your account settings so future forms are prefilled; otherwise we ask each time and store the
details only with that payment.
For credit packages and other purchases from Digiwava directly, we issue the receipt or tax invoice
ourselves and collect the same billing details in the same way. We use them to produce your documents and to
handle payment support, refunds, disputes, and tax records. Billing details are optional unless the checkout
says otherwise; if you provide none, you still receive the available receipt or an abbreviated tax invoice
based on your payment record and account name.
Technical Information
To keep our platform secure and functioning properly, we automatically collect technical information: your IP
address, information about your browser and device, session data that keeps you signed in, records of the
requests and pages you load, and error and performance reports. This information helps us detect unusual
activity, prevent unauthorized access, and fix problems across different devices.
Platform Visitors
Even if you do not create an account, we collect basic analytics data and technical information about your
browser and device when you visit our platform. This helps us understand how people use our marketplace and
improve the experience for all visitors. Technical information is collected through standard web server logs.
Our analytics service does not use cookies or track individual users.
AI Feature Information
When you use AI-powered features, we collect the prompts and settings you submit. For AI video generation,
this can include an optional reference image you upload, details of your request such as the model and
duration you selected, and the completed MP4 video generated from your request. For AI logo generation, this
can include the business details and prompts you submit, optional reference images you upload, details such as
the style and model you selected, and the generated logo images. Your prompts are sent to a third-party AI
provider to generate the requested output. Reference images, completed videos, and generated logos are stored
in your private Digiwava vault and protected by your account.
Support and Contact Information
If you contact us through the contact form, you provide a name, an email address, a subject, and a message so
we can respond. We keep your submission as long as necessary to handle and document your inquiry, and email
you send to our contact addresses is retained on the same basis.
Data We Do Not Request
Your account requires only a username and a single sign-in credential, which can be an email address, a
third-party sign-in such as Google, or a Web3 wallet address. If you do not provide them, we cannot create an
account for you; browsing the marketplace does not require an account. Additional profile information (such as
a bio, shop name, avatar, and social links) is entirely optional and only stored if you choose to provide it.
Your public profile has no fields for real names, phone numbers, or physical addresses. Business details
collected for invoicing (see Billing and Invoice Information above) are stored separately and used only for
receipt and tax invoice generation.
We do not ask you to upload government-issued identity documents or precise geolocation data. When sellers
need identity verification to receive payments, Stripe handles it on Stripe's platform, and Digiwava does not
receive the identity documents from Stripe. Do not submit them through profiles, chat, AI prompts, reference
images, or other uploads.
Free-text fields and uploads can contain personal data you choose to submit. These fields include profile
descriptions, chat messages, AI prompts, and reference images. Digiwava does not intentionally request
sensitive personal data as defined by the Thai PDPA, including health, disability, genetic or biometric data,
sexual behavior, religious or philosophical beliefs, political opinions, racial or ethnic origin, trade union
information, or criminal records. Do not submit sensitive personal data through Digiwava. Because user content
can contain unexpected information, we cannot guarantee that sensitive data is never received or processed. If
we identify it, we may restrict access to or delete it unless its retention or processing is required or
permitted by law. We do not use sensitive data submitted through user content for marketing or profiling.
2. How We Use Your Information
We use your information for specific, legitimate purposes to operate our marketplace. Under the Thai PDPA, we
process your data based on: consent (optional features, promotional emails if introduced), contract
performance (account creation, order fulfillment), legal obligations (tax reporting, lawful requests),
and legitimate interests (security, fraud prevention, service improvements).
To Provide Our Services
Your information enables us to create and manage your account, process orders and deliver digital products,
facilitate communication between buyers and sellers, provide customer support, and generate download links for
your purchases.
To Improve Our Platform
With your information, we can understand how people use our marketplace, identify and fix technical issues,
develop new features based on user needs, and ensure our platform works well across different devices and
browsers.
For Security and Trust
We use your information to protect our platform and users by preventing fraud and unauthorized access,
investigating violations of our Terms of Use, and resolving disputes between buyers and sellers.
This includes monitoring for unusual account activity and maintaining secure backups.
For Marketing and Analytics
We use a privacy-focused analytics service to understand how people use our marketplace. This service does not
use cookies, does not track individual users, and does not collect personal data. We do not currently use
advertising pixels or retargeting technologies. If we add these in the future, we will update this policy and
obtain your consent where required.
To Communicate With You
You will receive essential service emails including sign-in and password reset emails and important updates
about our terms or privacy policy. We do not currently send promotional emails. If we introduce them, we will
ask for your consent first, and every promotional message will include an unsubscribe link.
To Comply With Legal Obligations
We are required to use certain information to comply with legal obligations, including maintaining transaction
records for 5 years per Thai tax law, responding to valid legal requests
from authorities, and enforcing our Terms of Use to protect the platform and community.
3. How We Share Your Information
We share information only when needed to operate the platform, process payments, meet legal obligations, or
protect the service.
We never sell your personal data to third parties. We don't make your purchase history public or share it with
sellers beyond what is necessary for order fulfillment. We won't share your email with third parties for their
marketing purposes.
With Other Users
Certain information is public on our platform, including your username, avatar, any digital products you are
selling, and reviews you have written. When you complete a transaction, sellers can see your username and what
you purchased from them. Sellers act as independent data controllers of the information they receive through a
sale and must handle it in accordance with applicable data protection law.
With Service Providers
We work with trusted service providers to operate our marketplace:
Payment processing: Stripe handles payments and seller verification, receiving only transaction data
necessary to process payments securely.
Security and CDN: Cloudflare provides protection against attacks and content delivery, accessing
technical information like IP addresses.
Cloud infrastructure: Our hosting providers store platform data with strict security requirements.
Error monitoring and diagnostics: We use error monitoring services to find and fix technical problems,
investigate security events, and receive feedback you choose to send. These services receive technical
reports such as error details, browser and device information, IP addresses, the page and request involved,
and your account ID when it is part of the report. We strip message content, form input, cookies, and
sensitive request data before anything is sent.
Email delivery: An email delivery service sends our service and moderation emails, receiving recipient
email addresses and message content.
Contact and support services: Providers that handle contact forms and business email receive the contact
details and message content you send so we can review and respond to inquiries.
Analytics: We use privacy-focused analytics to understand platform usage (see
Section 1 and Section 2 for details).
Our primary service providers operate under terms that include data protection commitments.
For Legal Reasons
We may share information when required by law to comply with court orders, report income for tax purposes,
assist law enforcement with valid requests, or protect against fraud and security risks. We review each
request to ensure it is legally valid and only share the minimum information necessary.
With AI Service Providers
AI features on the platform run through OpenRouter, an AI routing service. OpenRouter selects an eligible
model provider for each request and can move that request to another eligible provider, so the provider that
handles any single request is not fixed in advance. The group of eligible downstream providers changes as
OpenRouter adds, removes, or reroutes model endpoints. When you use an AI-powered feature, the prompts,
settings, and reference images you submit may be processed by the selected provider so it can generate the
requested output. For video and logo generation, the provider returns the completed video or logo images to us
so we can store them privately in your Digiwava vault. For the YouTube summarizer, the YouTube link or video
ID you submit is also sent to Google's YouTube Data API to retrieve video details. OpenRouter and its
downstream providers have their own privacy policies and may use inputs according to their terms. Retention
windows for AI inputs, reference images, and generated videos and logos are described in
Section 4. AI-powered features are clearly labeled and entirely optional.
Every text and image AI request carries the same routing conditions: providers that would collect your data or
use it to train models are excluded, and so are providers that cannot handle the complete request. Video
generation is the exception because OpenRouter's asynchronous video API does not support those routing
conditions and is not eligible for zero data retention. The completed video must be retained temporarily so it
can be retrieved after generation.
Your shop data in the seller assistant. When you ask the seller assistant about your shop, it can read
your own records and include them in the request sent to the selected model provider. That includes purchase
records containing the buyer's username, the product title, the amounts, the status, and any discount code.
These are records you already hold as the seller, and asking the assistant about them sends them through the
routing service described above.
Assistant web search. The assistant can search the web when a question is not answered by your Digiwava
data. The search runs through OpenRouter, which uses either the selected model provider's own search or
another search provider. The model writes the search query itself, and that query can be based on what you
asked and on information the assistant retrieved from your own shop earlier in the same reply.
Direct mode. Any assistant can be switched to direct mode, which talks to the selected model without
Digiwava instructions and without Digiwava tools. In direct mode we send no instructions of our own, including
the Thai lese-majeste content restriction we apply in standard mode, and we do not screen the text you send
before it reaches the provider. The model provider's own policies still apply. Direct mode is remembered only
within the current browser tab, and switching modes starts a new, empty conversation, so direct mode receives
only what you enter after the switch.
We also provide a public API (MCP server) that lets third-party AI agents search our product catalog for their
users. When an AI agent uses it, we log the search text, the number of results, and the time, and keep that
record for 90 days. These records are not linked to a Digiwava account, but they are not
always anonymous: a search can itself contain identifying text, and our server logs can record the request's
IP address as described under Technical Information.
Connected AI clients. Sellers and administrators can connect a third-party AI client of their own choosing
to Digiwava. The client is chosen by the person connecting it: we keep no list of approved clients, and the
name a client reports about itself is not verified by us. Connecting requires signing in and approving the
exact access the client requested. A seller who approves access to identified sales sends purchase records
that identify buyers by username to the client that seller selected, and that client and its own AI provider
then process those records under their own terms. Sellers and administrators can revoke a connection at any
time in Settings. Revoking disconnects the client. The seller or administrator can approve a new connection
later. The client or its AI provider may retain records received from Digiwava. Those records are outside
Digiwava's control, and Digiwava cannot delete them. We keep a record of what a connected AI client does on
the account, described in Section 4.
Business Transfers
If Digiwava is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as
part of that transaction. We will notify you of any change in ownership or control of your personal data.
International Transfers
Your data may be processed outside Thailand as part of our global operations. Our primary infrastructure is
hosted in Singapore, providing optimal performance for Southeast Asian users. Payment processing occurs
through Stripe's global infrastructure, and we use content delivery networks across the ASEAN region for
better performance.
Transfers of personal data outside Thailand are subject to Thai PDPA Section 28 or another applicable PDPA
provision. Depending on the provider's role, destination, and processing activity, relevant contractual,
technical, and organizational measures can include:
Contractual data protection terms, data processing agreements, standard contractual clauses, or
equivalent transfer terms where required or available
Encryption for data in transit (TLS) and at rest where supported by the provider
Minimum necessary sharing so providers receive only the information needed for their role
4. Data Retention
We keep your data only as long as necessary. While your account is active, we maintain your profile
information, transaction history, and other account data. Some categories have a fixed lifecycle that applies
even while your account remains active:
Digiwava Chat history is retained for 90 days for both parties and then permanently
deleted. You will only ever see the last 90 days of conversations in your inbox, and
older messages are removed nightly. Save copies of anything you may need as support or dispute evidence
before it rolls off.
AI Assistant and AI tool inputs you submit (such as assistant prompts and YouTube links) and stored text
results (such as generated summaries) are retained for 90 days for rate limiting,
security, and redisplay of your results.
AI video and AI logo prompts, records of each generation job, generated MP4 videos, and generated logo
images are retained for 90 days while your account is active, then permanently
deleted. Saved reference images remain in your private Digiwava vault until you delete them from the
reference library or delete your account. Temporary copies used to run a job are deleted when the job
finishes. If your account is deleted, private AI vault content is removed immediately and is not restored.
Download access records include your IP address, country, and browser information for fraud prevention and
dispute resolution. These details are removed after 180 days.
The download record itself stays in your purchase history for 365
days from the download, then it is deleted.
Wishlist activity records note when an authenticated buyer saves a product, removes a saved product, or
purchases a saved product. They are retained for 90 days to provide sellers
and platform administrators with aggregate demand and conversion insights. A seller sees only aggregate
counts for their products, not buyer identities or individual wishlists.
Connector activity records show which connected AI client acted on an account, who authorized it, which tool
it used, when, and whether the action succeeded. They contain no tool inputs, results, or credentials. These
records are kept for 365 days so that misuse of a connection can be investigated
and so that disputes and support requests about an action taken through a connection can be resolved months
after it happened.
After account deletion (whether by you or per Terms of Use, Section 8), we
retain only the following data for the stated purposes and periods:
Financial records, including payment records, issued receipts and tax invoices, and the billing details they
contain, for 5 years per Thai tax law
Minimal purchase history showing what you bought, when, the transaction status, and whether access remains
available, for 5 years to support fulfillment, accounting, refunds,
disputes, and legal claims
Seller digital products for 6 months so buyers can access their purchases
Account restoration record (original username and sign-in identity, such as an email address or wallet
address) for 6 months to provide account recovery at your request
Account and security state needed for restoration, including the same account, sign-in credential, verified
MFA factors, current Digiwava credit balance, Digiwava seller tier, and pre-deletion suspension state, for
6 months
Any Digiwava Chat messages still within the 90-day window, to support dispute
resolution
Wishlist activity records still within the 90-day window, with links to the
deleted buyer or seller account removed, for aggregate demand and conversion reporting
User blocks until final account deletion, so deletion and restoration cannot bypass either party's safety
choices
Connector activity records for 365 days from the action they describe, so deleting
an account cannot erase the record of what a connected AI client did
Security and connection logs, which Thai law requires us to keep for at least 90 days; we keep them longer
only as needed to protect the platform
Backup copies are purged within 90 days. Data may be retained longer if required for legal proceedings or
regulatory investigations.
5. Your Privacy Rights
Under the Thai PDPA, you have rights over your personal data. The law grants you core rights including access,
rectification, erasure, data portability, objection, restriction of processing, and withdrawal of consent.
Honoring these rights does not require you to provide a reason, and you will never face discrimination or
degraded service for exercising them.
Access Your Data
Account settings lets you view and manage your profile, sign-in and security, billing, seller, and support
details. Your purchase history is available on the Purchases page, and sellers manage products they create
through seller product management. Sellers can also download their complete financial transaction history
directly from their Stripe Dashboard.
To receive a portable copy of your data, email privacy@digiwava.com from your registered email address. If
your account has no email address (for example, a Web3 wallet account), contact us and we will verify your
ownership via in-account confirmation before providing your data. We will provide your personal data in CSV
format within 30 days where technically feasible.
Update Your Information
If any of your information is incorrect or outdated, you can update most of it directly in your account
settings. For fields you cannot change yourself, contact us and we will assist you promptly.
Delete Your Account
You have the right to delete your account at any time. When you do:
Your profile is immediately anonymized (username, email, and personal details)
Your username changes to a random identifier
Your avatar is permanently removed
Reviews you have written are permanently deleted
Your votes, follows, support channels, current wishlist, buyer billing defaults, live seller billing
profile, seller onboarding state, unused seller discounts, and private AI vault content are permanently
deleted
Links from retained wishlist activity records to your buyer or seller account are removed immediately
We keep a private restoration record of your original username and sign-in identity for
6 months in case you change your mind (see Account Restoration below). After
6 months, this record and your account are permanently deleted.
We retain only the following categories after deletion, for the purposes and periods described in
Section 4:
Seller digital products remain available to buyers for 6 months
Financial records, including payment records, issued receipts and tax invoices, and the billing details they
contain, are kept for 5 years to comply with tax law
Minimal purchase history showing what you bought, when, the transaction status, and whether access remains
available is kept for 5 years to support fulfillment, accounting,
refunds, disputes, and legal claims
Account and security state needed for restoration, including the same account, sign-in credential, verified
MFA factors, current Digiwava credit balance, Digiwava seller tier, and pre-deletion suspension state, is
kept for 6 months
Any Digiwava Chat messages still within the standard 90-day retention window remain
restricted to dispute resolution (see Section 4)
Deidentified wishlist activity records remain only until the standard 90-day
expiry (see Section 4)
User blocks remain effective until final account deletion to preserve both parties' safety choices
Connector activity records are kept for 365 days from the action they describe (see
Section 4)
Security and connection logs are kept for at least 90 days as Thai law requires, and longer only as needed
to protect the platform
Account Restoration
If your account is deleted (whether by you or by us), you can request restoration within
6 months by emailing privacy@digiwava.com from your registered email address.
If your account has no email address (for example, a Web3 wallet account), contact us and we will verify your
ownership before restoring your account. Accounts terminated by us for violations of our
Terms of Use may not be eligible for restoration. We can restore your username and sign-in identity
from the private restoration record. Restoration also returns your private purchase history, any purchase
access still available under the product lifecycle, and seller products still within the product-retention
window. It also preserves your current Digiwava credit balance, Digiwava seller tier, verified MFA factors,
any pre-deletion account suspension that is still in effect, and existing user blocks. Restoration enables new
chat. Messages retained for disputes do not reappear in ordinary chat history and are deleted on the
Section 4 schedule. Deidentified wishlist activity is not reattached to the restored
account. Reviews, votes, follows, support channels, wishlists, buyer billing defaults, live seller billing
profile, seller onboarding state, avatars, private AI vault content, and other data deleted at account
deletion cannot be recovered. Your Stripe connection is not restored; you must reconnect Stripe, complete
seller onboarding again, and re-enter seller billing details before paid products can become eligible for sale
again. After 6 months, restoration is no longer possible as account data is
permanently deleted.
Withdraw Consent
Where we process your data based on consent (such as optional features or marketing communications), you have
the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any
processing carried out before the withdrawal. You can withdraw consent at any time by contacting us at
privacy@digiwava.com; promotional emails, if we introduce them, will also include an unsubscribe link.
Object and Restrict Processing
You have the right to object to certain uses of your data, particularly for marketing purposes or based on our
legitimate interests. You can also request that we temporarily restrict processing while we investigate
concerns or verify accuracy. Contact us to exercise these rights.
6. Security
We protect your personal data with multiple security measures.
How We Protect Your Data
All data is encrypted both in transit using HTTPS, which uses TLS, and at rest using industry-standard
encryption. Your password is secured with one-way hashing, making it impossible for anyone (including us) to
see your actual password. Our infrastructure is hosted in secure data centers with regular security audits.
Access to production systems is strictly limited, requires multi-factor authentication, and administrative
actions such as product moderation and account deletion are logged. We work with trusted security partners
including Stripe for PCI-compliant payment processing.
Data Breach Response
In the unlikely event of a data breach that affects your personal data, we will notify the Office of the
Personal Data Protection Committee (PDPC) within 72 hours as required by the Thai PDPA. If the breach poses
high risk to your rights and freedoms, we will also notify you directly without undue delay, explaining what
happened, what information was involved, and what steps you should take.
Your Role in Security
You can help keep your account secure by:
Using a strong, unique password and considering a password manager
Being cautious with unexpected emails claiming to be from us
Keeping your browser and operating system updated
Enabling two-factor authentication on your email account (used for password recovery)
Contacting us promptly if you notice unusual activity
When purchasing digital products, review seller ratings and product descriptions before buying. While we scan
uploaded files for malware, we recommend using antivirus software and exercising caution as you would with any
files downloaded from the internet.
7. Cookies
We use only essential cookies: authentication (to keep you signed in), language preference, and platform
operation. Blocking these cookies will prevent sign-in. We do not use analytics or advertising cookies.
Third-party services like Stripe and Cloudflare may set their own cookies for payment processing and security,
which are necessary for platform operation.
8. Children's Privacy
Our platform is intended for users aged 13 and older. We don't knowingly collect information from children
under 13. If we discover we've collected data from someone under 13, we'll promptly delete their account and
personal data, except where retention is required by law (see Section 4).
For users aged 13-19, parental consent is required under Terms of Use, Section 1.
Parents or guardians can contact us to request information about their child's account or request deletion.
The prohibition on submitting sensitive personal data applies to minors as well. We encourage parental
involvement in young users' online activities. Selling on the platform requires connecting a Stripe account,
which has its own age requirements (users under 18 need legal guardian approval).
9. Changes to This Policy
We may update this Privacy Policy from time to time. Minor changes like clarifications or formatting
improvements will be reflected in the updated date shown at the top of this page. For material changes that
significantly affect your rights or how we handle your data, we will notify you via email or platform
notification.
The current version will always be available at digiwava.com/privacy.
We verify your identity by confirming access to your registered email address or via in-account confirmation.
For requests we cannot fulfill (such as data required for legal compliance), we will explain why within the
response period.
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data
Protection Committee (PDPC) of Thailand at pdpc.or.th.