This policy explains how Digiwava Co., Ltd. collects, uses, discloses, and retains personal data under Thailand's Personal Data Protection Act (PDPA). It applies to anyone who accesses Digiwava. The full policy follows; here is the short version:
- Minimal by design. An account needs only a username and one sign-in credential; everything else is optional.
- Never sold. We never sell your personal data, and we use no advertising or tracking cookies.
- Payments stay with Stripe. Card details go directly to Stripe; we never receive full card numbers.
- Deleted on schedule. Chat messages and AI activity are deleted on the fixed schedules in Section 4.
- Delete anytime. You can delete your account yourself, and you can exercise every PDPA right at privacy@digiwava.com.
We collect only what we need to run the marketplace:
When you create an account, you provide a username (your public identifier on the platform). For sign-in, you can use an email address (kept private) with a password or a one-time sign-in link we email to you, a third-party provider such as Google, or a Web3 wallet (Ethereum or Solana). When you use a third-party provider, that provider shares basic account information with us, which is stored as part of your sign-in record; the exact details depend on the provider. When you sign in with a Web3 wallet, your public wallet address is stored and serves as your account identity; an account created this way has no email address unless you later add one in your settings. We use your email address, where one is present, to create and identify your account, and do not use the rest. You can optionally add profile enhancements like an avatar, about section, or shop name to personalize your presence on the platform.
For buyers, we maintain a private record of your purchases, including seller product purchases and platform-direct purchases such as credit packages, together with what you bought, when, the transaction status, download history where applicable, and your current wishlist items. We also record when an authenticated buyer adds or removes a wishlist item and when a saved item is purchased, as described in Section 4.
For sellers, we track your digital product listings, sales metrics, and performance data to help you understand your business.
Reviews you write become public and associated with your username.
We do not receive or store full card numbers, security codes, or payment credentials. When you make a purchase, you enter those details into Stripe's secure form embedded on our checkout page. They go directly to Stripe's PCI-compliant servers. Stripe provides us with limited transaction and card metadata, such as the transaction ID, payment status, payment method type, and the card's last four digits where applicable.
For sellers, Stripe handles all identity verification, tax documentation, and banking details directly on their platform. We store only your Stripe account ID. Payouts flow directly from Stripe to your bank account. We do not hold your funds, but we may request Stripe to pause payouts to your account if we detect suspicious activity or to comply with Stripe's requirements (see Terms of Use, Section 4.6).
The platform generates receipts and tax invoices for purchases. What we collect depends on your role:
Sellers who list paid products provide business details for their receipts: a business name, a tax identification number (TIN), and optionally a phone number. VAT-registered sellers also provide a business address and branch code. These details are stored separately from your public profile and appear only on the receipts and tax invoices issued to your buyers.
Buyers never need to provide billing details to purchase. If you want a full tax invoice, you provide the name to show on it, a TIN, a billing address, and optional branch details, either at checkout or, for eligible purchases, later from your Purchases page, where you can also correct an invoice that was issued with wrong details. Full tax invoices are available for purchases from VAT-registered sellers. You can save these details in your account settings so future forms are prefilled; otherwise we ask each time and store the details only with that payment.
For credit packages and other purchases from Digiwava directly, we issue the receipt or tax invoice ourselves and collect the same billing details in the same way. We use them to produce your documents and to handle payment support, refunds, disputes, and tax records. Billing details are optional unless the checkout says otherwise; if you provide none, you still receive the available receipt or an abbreviated tax invoice based on your payment record and account name.
To keep our platform secure and functioning properly, we automatically collect technical information: your IP address, information about your browser and device, session data that keeps you signed in, records of the requests and pages you load, and error and performance reports. This information helps us detect unusual activity, prevent unauthorized access, and fix problems across different devices.
Even if you do not create an account, we collect basic analytics data and technical information about your browser and device when you visit our platform. This helps us understand how people use our marketplace and improve the experience for all visitors. Technical information is collected through standard web server logs. Our analytics service does not use cookies or track individual users.
When you use AI-powered features, we collect the prompts and settings you submit. For AI video generation, this can include an optional reference image you upload, details of your request such as the model and duration you selected, and the completed MP4 video generated from your request. For AI logo generation, this can include the business details and prompts you submit, optional reference images you upload, details such as the style and model you selected, and the generated logo images. Your prompts are sent to a third-party AI provider to generate the requested output. Reference images, completed videos, and generated logos are stored in your private Digiwava vault and protected by your account.
If you contact us through the contact form, you provide a name, an email address, a subject, and a message so we can respond. We keep your submission as long as necessary to handle and document your inquiry, and email you send to our contact addresses is retained on the same basis.
Your account requires only a username and a single sign-in credential, which can be an email address, a third-party sign-in such as Google, or a Web3 wallet address. If you do not provide them, we cannot create an account for you; browsing the marketplace does not require an account. Additional profile information (such as a bio, shop name, avatar, and social links) is entirely optional and only stored if you choose to provide it. Your public profile has no fields for real names, phone numbers, or physical addresses. Business details collected for invoicing (see Billing and Invoice Information above) are stored separately and used only for receipt and tax invoice generation.
We do not ask you to upload government-issued identity documents or precise geolocation data. When sellers need identity verification to receive payments, Stripe handles it on Stripe's platform, and Digiwava does not receive the identity documents from Stripe. Do not submit them through profiles, chat, AI prompts, reference images, or other uploads.
Free-text fields and uploads can contain personal data you choose to submit. These fields include profile descriptions, chat messages, AI prompts, and reference images. Digiwava does not intentionally request sensitive personal data as defined by the Thai PDPA, including health, disability, genetic or biometric data, sexual behavior, religious or philosophical beliefs, political opinions, racial or ethnic origin, trade union information, or criminal records. Do not submit sensitive personal data through Digiwava. Because user content can contain unexpected information, we cannot guarantee that sensitive data is never received or processed. If we identify it, we may restrict access to or delete it unless its retention or processing is required or permitted by law. We do not use sensitive data submitted through user content for marketing or profiling.
We use your information for specific, legitimate purposes to operate our marketplace. Under the Thai PDPA, we process your data based on: consent (optional features, promotional emails if introduced), contract performance (account creation, order fulfillment), legal obligations (tax reporting, lawful requests), and legitimate interests (security, fraud prevention, service improvements).
Your information enables us to create and manage your account, process orders and deliver digital products, facilitate communication between buyers and sellers, provide customer support, and generate download links for your purchases.
With your information, we can understand how people use our marketplace, identify and fix technical issues, develop new features based on user needs, and ensure our platform works well across different devices and browsers.
We use your information to protect our platform and users by preventing fraud and unauthorized access, investigating violations of our Terms of Use, and resolving disputes between buyers and sellers. This includes monitoring for unusual account activity and maintaining secure backups.
We use a privacy-focused analytics service to understand how people use our marketplace. This service does not use cookies, does not track individual users, and does not collect personal data. We do not currently use advertising pixels or retargeting technologies. If we add these in the future, we will update this policy and obtain your consent where required.
You will receive essential service emails including sign-in and password reset emails and important updates about our terms or privacy policy. We do not currently send promotional emails. If we introduce them, we will ask for your consent first, and every promotional message will include an unsubscribe link.
We are required to use certain information to comply with legal obligations, including maintaining transaction records for 5 years per Thai tax law, responding to valid legal requests from authorities, and enforcing our Terms of Use to protect the platform and community.
We share information only when needed to operate the platform, process payments, meet legal obligations, or protect the service.
We never sell your personal data to third parties. We don't make your purchase history public or share it with sellers beyond what is necessary for order fulfillment. We won't share your email with third parties for their marketing purposes.
Certain information is public on our platform, including your username, avatar, any digital products you are selling, and reviews you have written. When you complete a transaction, sellers can see your username and what you purchased from them. Sellers act as independent data controllers of the information they receive through a sale and must handle it in accordance with applicable data protection law.
We work with trusted service providers to operate our marketplace:
- Payment processing: Stripe handles payments and seller verification, receiving only transaction data necessary to process payments securely.
- Security and CDN: Cloudflare provides protection against attacks and content delivery, accessing technical information like IP addresses.
- Cloud infrastructure: Our hosting providers store platform data with strict security requirements.
- Error monitoring and diagnostics: We use error monitoring services to find and fix technical problems, investigate security events, and receive feedback you choose to send. These services receive technical reports such as error details, browser and device information, IP addresses, the page and request involved, and your account ID when it is part of the report. We strip message content, form input, cookies, and sensitive request data before anything is sent.
- Email delivery: An email delivery service sends our service and moderation emails, receiving recipient email addresses and message content.
- Contact and support services: Providers that handle contact forms and business email receive the contact details and message content you send so we can review and respond to inquiries.
- Analytics: We use privacy-focused analytics to understand platform usage (see Section 1 and Section 2 for details).
Our primary service providers operate under terms that include data protection commitments.
We may share information when required by law to comply with court orders, report income for tax purposes, assist law enforcement with valid requests, or protect against fraud and security risks. We review each request to ensure it is legally valid and only share the minimum information necessary.
AI features on the platform run through OpenRouter, an AI routing service. OpenRouter selects an eligible model provider for each request and can move that request to another eligible provider, so the provider that handles any single request is not fixed in advance. The group of eligible downstream providers changes as OpenRouter adds, removes, or reroutes model endpoints. When you use an AI-powered feature, the prompts, settings, and reference images you submit may be processed by the selected provider so it can generate the requested output. For video and logo generation, the provider returns the completed video or logo images to us so we can store them privately in your Digiwava vault. For the YouTube summarizer, the YouTube link or video ID you submit is also sent to Google's YouTube Data API to retrieve video details. OpenRouter and its downstream providers have their own privacy policies and may use inputs according to their terms. Retention windows for AI inputs, reference images, and generated videos and logos are described in Section 4. AI-powered features are clearly labeled and entirely optional.
Every text and image AI request carries the same routing conditions: providers that would collect your data or use it to train models are excluded, and so are providers that cannot handle the complete request. Video generation is the exception because OpenRouter's asynchronous video API does not support those routing conditions and is not eligible for zero data retention. The completed video must be retained temporarily so it can be retrieved after generation.
Your shop data in the seller assistant. When you ask the seller assistant about your shop, it can read your own records and include them in the request sent to the selected model provider. That includes purchase records containing the buyer's username, the product title, the amounts, the status, and any discount code. These are records you already hold as the seller, and asking the assistant about them sends them through the routing service described above.
Assistant web search. The assistant can search the web when a question is not answered by your Digiwava data. The search runs through OpenRouter, which uses either the selected model provider's own search or another search provider. The model writes the search query itself, and that query can be based on what you asked and on information the assistant retrieved from your own shop earlier in the same reply.
Direct mode. Any assistant can be switched to direct mode, which talks to the selected model without Digiwava instructions and without Digiwava tools. In direct mode we send no instructions of our own, including the Thai lese-majeste content restriction we apply in standard mode, and we do not screen the text you send before it reaches the provider. The model provider's own policies still apply. Direct mode is remembered only within the current browser tab, and switching modes starts a new, empty conversation, so direct mode receives only what you enter after the switch.
We also provide a public API (MCP server) that lets third-party AI agents search our product catalog for their users. When an AI agent uses it, we log the search text, the number of results, and the time, and keep that record for 90 days. These records are not linked to a Digiwava account, but they are not always anonymous: a search can itself contain identifying text, and our server logs can record the request's IP address as described under Technical Information.
Connected AI clients. Sellers and administrators can connect a third-party AI client of their own choosing to Digiwava. The client is chosen by the person connecting it: we keep no list of approved clients, and the name a client reports about itself is not verified by us. Connecting requires signing in and approving the exact access the client requested. A seller who approves access to identified sales sends purchase records that identify buyers by username to the client that seller selected, and that client and its own AI provider then process those records under their own terms. Sellers and administrators can revoke a connection at any time in Settings. Revoking disconnects the client. The seller or administrator can approve a new connection later. The client or its AI provider may retain records received from Digiwava. Those records are outside Digiwava's control, and Digiwava cannot delete them. We keep a record of what a connected AI client does on the account, described in Section 4.
If Digiwava is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal data.
Your data may be processed outside Thailand as part of our global operations. Our primary infrastructure is hosted in Singapore, providing optimal performance for Southeast Asian users. Payment processing occurs through Stripe's global infrastructure, and we use content delivery networks across the ASEAN region for better performance.
Transfers of personal data outside Thailand are subject to Thai PDPA Section 28 or another applicable PDPA provision. Depending on the provider's role, destination, and processing activity, relevant contractual, technical, and organizational measures can include:
- Contractual data protection terms, data processing agreements, standard contractual clauses, or equivalent transfer terms where required or available
- Encryption for data in transit (TLS) and at rest where supported by the provider
- Minimum necessary sharing so providers receive only the information needed for their role
We keep your data only as long as necessary. While your account is active, we maintain your profile information, transaction history, and other account data. Some categories have a fixed lifecycle that applies even while your account remains active:
- Digiwava Chat history is retained for 90 days for both parties and then permanently deleted. You will only ever see the last 90 days of conversations in your inbox, and older messages are removed nightly. Save copies of anything you may need as support or dispute evidence before it rolls off.
- AI Assistant and AI tool inputs you submit (such as assistant prompts and YouTube links) and stored text results (such as generated summaries) are retained for 90 days for rate limiting, security, and redisplay of your results.
- AI video and AI logo prompts, records of each generation job, generated MP4 videos, and generated logo images are retained for 90 days while your account is active, then permanently deleted. Saved reference images remain in your private Digiwava vault until you delete them from the reference library or delete your account. Temporary copies used to run a job are deleted when the job finishes. If your account is deleted, private AI vault content is removed immediately and is not restored.
- Download access records include your IP address, country, and browser information for fraud prevention and dispute resolution. These details are removed after 180 days. The download record itself stays in your purchase history for 365 days from the download, then it is deleted.
- Wishlist activity records note when an authenticated buyer saves a product, removes a saved product, or purchases a saved product. They are retained for 90 days to provide sellers and platform administrators with aggregate demand and conversion insights. A seller sees only aggregate counts for their products, not buyer identities or individual wishlists.
- Connector activity records show which connected AI client acted on an account, who authorized it, which tool it used, when, and whether the action succeeded. They contain no tool inputs, results, or credentials. These records are kept for 365 days so that misuse of a connection can be investigated and so that disputes and support requests about an action taken through a connection can be resolved months after it happened.
After account deletion (whether by you or per Terms of Use, Section 8), we retain only the following data for the stated purposes and periods:
- Financial records, including payment records, issued receipts and tax invoices, and the billing details they contain, for 5 years per Thai tax law
- Minimal purchase history showing what you bought, when, the transaction status, and whether access remains available, for 5 years to support fulfillment, accounting, refunds, disputes, and legal claims
- Seller digital products for 6 months so buyers can access their purchases
- Account restoration record (original username and sign-in identity, such as an email address or wallet address) for 6 months to provide account recovery at your request
- Account and security state needed for restoration, including the same account, sign-in credential, verified MFA factors, current Digiwava credit balance, Digiwava seller tier, and pre-deletion suspension state, for 6 months
- Any Digiwava Chat messages still within the 90-day window, to support dispute resolution
- Wishlist activity records still within the 90-day window, with links to the deleted buyer or seller account removed, for aggregate demand and conversion reporting
- User blocks until final account deletion, so deletion and restoration cannot bypass either party's safety choices
- Connector activity records for 365 days from the action they describe, so deleting an account cannot erase the record of what a connected AI client did
- Security and connection logs, which Thai law requires us to keep for at least 90 days; we keep them longer only as needed to protect the platform
Backup copies are purged within 90 days. Data may be retained longer if required for legal proceedings or regulatory investigations.
Under the Thai PDPA, you have rights over your personal data. The law grants you core rights including access, rectification, erasure, data portability, objection, restriction of processing, and withdrawal of consent. Honoring these rights does not require you to provide a reason, and you will never face discrimination or degraded service for exercising them.
Account settings lets you view and manage your profile, sign-in and security, billing, seller, and support details. Your purchase history is available on the Purchases page, and sellers manage products they create through seller product management. Sellers can also download their complete financial transaction history directly from their Stripe Dashboard.
To receive a portable copy of your data, email privacy@digiwava.com from your registered email address. If your account has no email address (for example, a Web3 wallet account), contact us and we will verify your ownership via in-account confirmation before providing your data. We will provide your personal data in CSV format within 30 days where technically feasible.
If any of your information is incorrect or outdated, you can update most of it directly in your account settings. For fields you cannot change yourself, contact us and we will assist you promptly.
You have the right to delete your account at any time. When you do:
- Your profile is immediately anonymized (username, email, and personal details)
- Your username changes to a random identifier
- Your avatar is permanently removed
- Reviews you have written are permanently deleted
- Your votes, follows, support channels, current wishlist, buyer billing defaults, live seller billing profile, seller onboarding state, unused seller discounts, and private AI vault content are permanently deleted
- Links from retained wishlist activity records to your buyer or seller account are removed immediately
We keep a private restoration record of your original username and sign-in identity for 6 months in case you change your mind (see Account Restoration below). After 6 months, this record and your account are permanently deleted.
We retain only the following categories after deletion, for the purposes and periods described in Section 4:
- Seller digital products remain available to buyers for 6 months
- Financial records, including payment records, issued receipts and tax invoices, and the billing details they contain, are kept for 5 years to comply with tax law
- Minimal purchase history showing what you bought, when, the transaction status, and whether access remains available is kept for 5 years to support fulfillment, accounting, refunds, disputes, and legal claims
- Account and security state needed for restoration, including the same account, sign-in credential, verified MFA factors, current Digiwava credit balance, Digiwava seller tier, and pre-deletion suspension state, is kept for 6 months
- Any Digiwava Chat messages still within the standard 90-day retention window remain restricted to dispute resolution (see Section 4)
- Deidentified wishlist activity records remain only until the standard 90-day expiry (see Section 4)
- User blocks remain effective until final account deletion to preserve both parties' safety choices
- Connector activity records are kept for 365 days from the action they describe (see Section 4)
- Security and connection logs are kept for at least 90 days as Thai law requires, and longer only as needed to protect the platform
If your account is deleted (whether by you or by us), you can request restoration within 6 months by emailing privacy@digiwava.com from your registered email address. If your account has no email address (for example, a Web3 wallet account), contact us and we will verify your ownership before restoring your account. Accounts terminated by us for violations of our Terms of Use may not be eligible for restoration. We can restore your username and sign-in identity from the private restoration record. Restoration also returns your private purchase history, any purchase access still available under the product lifecycle, and seller products still within the product-retention window. It also preserves your current Digiwava credit balance, Digiwava seller tier, verified MFA factors, any pre-deletion account suspension that is still in effect, and existing user blocks. Restoration enables new chat. Messages retained for disputes do not reappear in ordinary chat history and are deleted on the Section 4 schedule. Deidentified wishlist activity is not reattached to the restored account. Reviews, votes, follows, support channels, wishlists, buyer billing defaults, live seller billing profile, seller onboarding state, avatars, private AI vault content, and other data deleted at account deletion cannot be recovered. Your Stripe connection is not restored; you must reconnect Stripe, complete seller onboarding again, and re-enter seller billing details before paid products can become eligible for sale again. After 6 months, restoration is no longer possible as account data is permanently deleted.
Where we process your data based on consent (such as optional features or marketing communications), you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal. You can withdraw consent at any time by contacting us at privacy@digiwava.com; promotional emails, if we introduce them, will also include an unsubscribe link.
You have the right to object to certain uses of your data, particularly for marketing purposes or based on our legitimate interests. You can also request that we temporarily restrict processing while we investigate concerns or verify accuracy. Contact us to exercise these rights.
We protect your personal data with multiple security measures.
All data is encrypted both in transit using HTTPS, which uses TLS, and at rest using industry-standard encryption. Your password is secured with one-way hashing, making it impossible for anyone (including us) to see your actual password. Our infrastructure is hosted in secure data centers with regular security audits. Access to production systems is strictly limited, requires multi-factor authentication, and administrative actions such as product moderation and account deletion are logged. We work with trusted security partners including Stripe for PCI-compliant payment processing.
In the unlikely event of a data breach that affects your personal data, we will notify the Office of the Personal Data Protection Committee (PDPC) within 72 hours as required by the Thai PDPA. If the breach poses high risk to your rights and freedoms, we will also notify you directly without undue delay, explaining what happened, what information was involved, and what steps you should take.
You can help keep your account secure by:
- Using a strong, unique password and considering a password manager
- Being cautious with unexpected emails claiming to be from us
- Keeping your browser and operating system updated
- Enabling two-factor authentication on your email account (used for password recovery)
- Contacting us promptly if you notice unusual activity
When purchasing digital products, review seller ratings and product descriptions before buying. While we scan uploaded files for malware, we recommend using antivirus software and exercising caution as you would with any files downloaded from the internet.
We use only essential cookies: authentication (to keep you signed in), language preference, and platform operation. Blocking these cookies will prevent sign-in. We do not use analytics or advertising cookies.
Third-party services like Stripe and Cloudflare may set their own cookies for payment processing and security, which are necessary for platform operation.
Our platform is intended for users aged 13 and older. We don't knowingly collect information from children under 13. If we discover we've collected data from someone under 13, we'll promptly delete their account and personal data, except where retention is required by law (see Section 4).
For users aged 13-19, parental consent is required under Terms of Use, Section 1. Parents or guardians can contact us to request information about their child's account or request deletion. The prohibition on submitting sensitive personal data applies to minors as well. We encourage parental involvement in young users' online activities. Selling on the platform requires connecting a Stripe account, which has its own age requirements (users under 18 need legal guardian approval).
We may update this Privacy Policy from time to time. Minor changes like clarifications or formatting improvements will be reflected in the updated date shown at the top of this page. For material changes that significantly affect your rights or how we handle your data, we will notify you via email or platform notification.
The current version will always be available at digiwava.com/privacy.
Data Controller: Digiwava Co., Ltd.
Email: privacy@digiwava.com
Response time: Within 30 days
We verify your identity by confirming access to your registered email address or via in-account confirmation. For requests we cannot fulfill (such as data required for legal compliance), we will explain why within the response period.
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand at pdpc.or.th.