DigiwavaDigiwava
Sell
Sign inSign up
Digiwava

A market for digital work, built for Thailand.

XInstagramFacebookYouTubeTikTok

Marketplace

  • All products
  • Sell
  • Tools
  • MCP
  • FAQ

Company

  • About
  • Contact
  • Status(opens in a new tab)
  • Privacy
  • Terms

© 2026 Digiwava Co., Ltd. All rights reserved.

FAQTerms of UsePrivacy Policy

Privacy Policy

Updated 28 August 202624 min read

On this page

  • 1. Information We Collect
    • Account Information
    • Transaction Information
    • Payment Information
    • Billing and Invoice Information
    • Technical Information
    • Platform Visitors
    • AI Feature Information
    • Support and Contact Information
    • Data We Do Not Request
  • 2. How We Use Your Information
    • To Provide Our Services
    • To Improve Our Platform
    • For Security and Trust
    • For Marketing and Analytics
    • To Communicate With You
    • To Comply With Legal Obligations
  • 3. How We Share Your Information
    • With Other Users
    • With Service Providers
    • For Legal Reasons
    • With AI Service Providers
    • Business Transfers
    • International Transfers
  • 4. Data Retention
  • 5. Your Privacy Rights
    • Access Your Data
    • Update Your Information
    • Delete Your Account
    • Account Restoration
    • Withdraw Consent
    • Object and Restrict Processing
  • 6. Security
    • How We Protect Your Data
    • Data Breach Response
    • Your Role in Security
  • 7. Cookies
  • 8. Children's Privacy
  • 9. Changes to This Policy
  • 10. Contact

This policy explains how Digiwava Co., Ltd. collects, uses, discloses, and retains personal data under Thailand's Personal Data Protection Act (PDPA). It applies to anyone who accesses Digiwava. The full policy follows; here is the short version:

  • Minimal by design. An account needs only a username and one sign-in credential; everything else is optional.
  • Never sold. We never sell your personal data, and Digiwava does not place cookies for its own advertising.
  • Payments stay with Stripe. Card details go directly to Stripe; we never receive full card numbers.
  • Deleted on schedule. Chat messages and AI activity follow the retention schedules in Section 4.
  • Delete anytime. You can delete your account yourself, and you can exercise every PDPA right at privacy@digiwava.com.

1. Information We Collect

We collect only what we need to run the marketplace:

Account Information

When you create an account, you provide a username (your public identifier on the platform). For sign-in, you can use an email address (kept private) with a password or a one-time sign-in link we email to you, a third-party provider such as Google, or a Web3 wallet (Ethereum or Solana). When you use a third-party provider, that provider shares basic account information with us, which is stored as part of your sign-in record; the exact details depend on the provider. When you sign in with a Web3 wallet, your public wallet address is stored and serves as your account identity; an account created this way has no email address unless you later add one in your settings. We use your email address, where one is present, to create and identify your account, and do not use the rest. You can optionally add profile enhancements like an avatar, about section, or shop name to personalize your presence on the platform.

Transaction Information

For buyers, we maintain a private record of your seller product purchases, including what you bought, when, the transaction status, download history where applicable, and your current wishlist items. We also record when an authenticated buyer adds or removes a wishlist item and when a saved item is purchased, as described in Section 4.

For sellers, we track your digital product listings, sales metrics, and performance data to help you understand your business.

Reviews you write become public and associated with your username.

Payment Information

We do not receive or store full card numbers, security codes, or payment credentials. When you make a purchase, you enter those details into Stripe's secure form embedded on our checkout page. They go directly to Stripe's PCI-compliant servers. Stripe provides us with limited transaction and card metadata, such as the transaction ID, payment status, payment method type, and the card's last four digits where applicable.

We also store the trusted server-observed IP address when you attempt to pay for a product, together with its payment-attempt record. We use it only for fraud prevention and payment-dispute evidence, keep it out of buyer and seller payment views, and remove it after 180 days. If the request does not reach us through a trusted network proxy, we do not infer an address from forwarding headers.

When a buyer disputes a seller product payment, Digiwava records the dispute so the sale, receipt, and access state stay accurate, and shows the seller the amount, reason, status, and response deadline. Digiwava does not assemble, stage, or submit dispute evidence, and never sends your download or payment records to Stripe for a dispute. The seller responds to the dispute entirely in their own Stripe account.

Stripe also uses cookies and similar technologies when you visit Digiwava to collect your IP address, identifying information about your browser or device, and activity indicators. Stripe uses this information to operate and improve its services, including fraud and loss prevention, authentication, and analysis of service performance. This collection occurs whether or not you are signed in. Stripe does not use its advanced fraud signals for advertising and retains them for as long as useful for fraud detection and security under its privacy policy(opens in a new tab) and cookie policy(opens in a new tab).

For sellers, Stripe handles all identity verification, tax documentation, and banking details directly on their platform. We store only your Stripe account ID. Payouts flow directly from Stripe to your bank account. We do not hold your funds, but we may request Stripe to pause payouts to your account if we detect suspicious activity or to comply with Stripe's requirements (see ).

Billing and Invoice Information

The platform generates receipts and tax invoices for purchases. What we collect depends on your role:

Sellers who list paid products provide business details for their receipts: a business name, a tax identification number (TIN), and optionally a phone number. VAT-registered sellers also provide a business address and branch code. These details are stored separately from your public profile and appear only on the receipts and tax invoices issued to your buyers.

Buyers never need to provide billing details to purchase. If you want a full tax invoice, you provide the name to show on it, a TIN, a billing address, and optional branch details, either at checkout or, for eligible purchases, later from your page, where you can also correct an invoice that was issued with wrong details. Full tax invoices are available for purchases from VAT-registered sellers. You can save these details in your account settings so future forms are prefilled; otherwise we ask each time and store the details only with that payment.

Technical Information

To keep our platform secure and functioning properly, we automatically collect technical information: your IP address, information about your browser and device, session data that keeps you signed in, records of the requests and pages you load, and error and performance reports. This information helps us detect unusual activity, prevent unauthorized access, and fix problems across different devices.

Platform Visitors

Even if you do not create an account, we collect basic analytics data and technical information about your browser and device when you visit our platform. This helps us understand how people use our marketplace and improve the experience for all visitors. Technical information is collected through standard web server logs and browser technologies used for security and payment-fraud prevention. Our analytics service does not use cookies or track individual users.

AI Feature Information

When you use the AI Assistant, we collect the prompts and bounded page context you submit. This can include your conversation and shop records that the seller assistant reads at your request. Your request is sent to a third-party AI provider to generate the requested output. We also log the model-facing input and generated output with our error-monitoring provider to diagnose AI performance and failures.

Support and Contact Information

If you contact us through the contact form, you provide a name, an email address, a subject, and a message so we can respond. We keep your submission as long as necessary to handle and document your inquiry, and email you send to our contact addresses is retained on the same basis.

Data We Do Not Request

Your account requires only a username and a single sign-in credential, which can be an email address, a third-party sign-in such as Google, or a Web3 wallet address. If you do not provide them, we cannot create an account for you; browsing the marketplace does not require an account. Additional profile information (such as a bio, shop name, avatar, and social links) is entirely optional and only stored if you choose to provide it. Your public profile has no fields for real names, phone numbers, or physical addresses. Business details collected for invoicing (see Billing and Invoice Information above) are stored separately and used only for receipt and tax invoice generation.

We do not ask you to upload government-issued identity documents or precise geolocation data. When sellers need identity verification to receive payments, Stripe handles it on Stripe's platform, and Digiwava does not receive the identity documents from Stripe. Do not submit them through profiles, chat, AI prompts, or other uploads.

Free-text fields and uploads can contain personal data you choose to submit. These fields include profile descriptions, chat messages, and AI prompts. Digiwava does not intentionally request sensitive personal data as defined by the Thai PDPA, including health, disability, genetic or biometric data, sexual behavior, religious or philosophical beliefs, political opinions, racial or ethnic origin, trade union information, or criminal records. Do not submit sensitive personal data through Digiwava. Because user content can contain unexpected information, we cannot guarantee that sensitive data is never received or processed. If we identify it, we may restrict access to or delete it unless its retention or processing is required or permitted by law. We do not use sensitive data submitted through user content for marketing or profiling.

When you submit an avatar or product preview, the original image can contain hidden metadata such as camera details, timestamps, or location data. Digiwava keeps signed-upload originals in private temporary storage. For preview URL imports, Digiwava keeps the downloaded source only in a limited memory buffer. Our server orients, resizes when needed, and re-encodes every accepted image. This process removes embedded EXIF, XMP, IPTC, comments, and thumbnails. Only the new canonical image becomes public. We delete temporary originals after processing or through delayed cleanup after the upload credential is no longer usable.

2. How We Use Your Information

We use your information for specific, legitimate purposes to operate our marketplace. Under the Thai PDPA, we process your data based on: consent (optional features, promotional emails if introduced), contract performance (account creation, order fulfillment), legal obligations (tax reporting, lawful requests), and legitimate interests (security, fraud prevention, service improvements).

To Provide Our Services

Your information enables us to create and manage your account, process orders and deliver digital products, facilitate communication between buyers and sellers, provide customer support, and generate download links for your purchases.

To Improve Our Platform

With your information, we can understand how people use our marketplace, identify and fix technical issues, develop new features based on user needs, and ensure our platform works well across different devices and browsers.

For Security and Trust

We use your information to protect our platform and users by preventing fraud and unauthorized access, investigating violations of our , and resolving disputes between buyers and sellers. This includes monitoring for unusual account activity and maintaining secure backups.

For Marketing and Analytics

We use a privacy-focused analytics service to understand how people use our marketplace. This service does not use cookies, does not track individual users, and does not collect personal data. We do not currently use advertising pixels or retargeting technologies. If we add these in the future, we will update this policy and obtain your consent where required.

To Communicate With You

You will receive essential service emails including sign-in and password reset emails and important updates about our terms or privacy policy. We do not currently send promotional emails. If we introduce them, we will ask for your consent first, and every promotional message will include an unsubscribe link.

To Comply With Legal Obligations

We are required to use certain information to comply with legal obligations, including maintaining transaction records for 5 years per Thai tax law, responding to valid legal requests from authorities, and enforcing our to protect the platform and community.

3. How We Share Your Information

We share information only when needed to operate the platform, process payments, meet legal obligations, or protect the service.

We never sell your personal data to third parties. We don't make your purchase history public or share it with sellers beyond what is necessary for order fulfillment. We won't share your email with third parties for their marketing purposes.

With Other Users

Certain information is public on our platform, including your username, avatar, any digital products you are selling, and reviews you have written. When you complete a transaction, sellers can see your username and what you purchased from them. If you request a full tax invoice, the seller also receives the invoice name, TIN, billing address, and any branch details needed to issue and retain that invoice. Sellers act as independent data controllers of the information they receive through a sale and must handle it in accordance with applicable data protection law.

With Service Providers

We work with trusted service providers to operate our marketplace:

  • Payment processing, fraud prevention, and disputes: Stripe handles payments, seller verification, and disputes. Stripe receives transaction and billing information plus IP addresses, device and browser identifiers, cookie data, and activity indicators to process payments, authenticate users, and detect fraud and loss. A seller responds to a dispute in their own Stripe account, and Stripe can provide the evidence the seller submits there to card networks and the buyer's card issuer. Digiwava submits no dispute evidence.
  • Security and CDN: Cloudflare provides protection against attacks and content delivery, accessing technical information like IP addresses.
  • Cloud infrastructure: Our hosting providers store platform data with strict security requirements.
  • Error monitoring and diagnostics: We use error monitoring services to find and fix technical problems, investigate security events, and receive feedback you choose to send. These services receive technical reports such as error details, browser and device information, IP addresses, the page and request involved, and your account ID when it is part of the report. Our application telemetry strips message content, form input, cookies, and sensitive request data. The AI Assistant diagnostic traces described below are the limited exception and include data sent to and received from the model.
  • Email delivery: An email delivery service sends our service and moderation emails, receiving recipient email addresses and message content.
  • Contact and support services: Providers that handle contact forms and business email receive the contact details and message content you send so we can review and respond to inquiries.
  • Analytics: We use privacy-focused analytics to understand platform usage (see Section 1 and Section 2 for details).
  • Embedded video: Product and review pages can load privacy-enhanced YouTube players. When a player loads, Google receives technical and usage information such as the page URL, IP address, browser and device information, and player interactions. Privacy-enhanced mode prevents that view from personalizing the viewer's YouTube experience, but the player can use cookies and show non-personalized ads under Google's Privacy Policy(opens in a new tab).

Our primary service providers operate under terms that include data protection commitments.

For Legal Reasons

We may share information when required by law to comply with court orders, report income for tax purposes, assist law enforcement with valid requests, or protect against fraud and security risks. We review each request to ensure it is legally valid and only share the minimum information necessary.

With AI Service Providers

AI features on the platform run through OpenRouter, an AI routing service. OpenRouter selects an eligible model provider for each request and can move that request to another eligible provider, so the provider that handles any single request is not fixed in advance. The group of eligible downstream providers changes as OpenRouter adds, removes, or reroutes model endpoints. When you use the AI Assistant, the prompts and context you submit may be processed by the routed provider so it can generate the requested output. OpenRouter and its downstream providers have their own privacy policies and may use inputs according to their terms. Digiwava's storage of Assistant activity is described in Section 4. AI-powered features are clearly labeled and entirely optional.

Every AI text request carries the same routing conditions: providers that would collect your data or use it to train models are excluded, and so are providers that cannot handle the complete request.

OpenRouter also sends a copy of every AI Assistant model request and response to our error-monitoring provider. This can include system instructions, recent conversation text, bounded page context, and, in seller or administrator flows, model-facing tool calls and the records returned by those tools. We use these traces to diagnose Assistant errors, performance, and output quality.

Your shop data in the seller assistant. When you ask the seller assistant about your shop, it can read your own records and include them in the request sent to the routed model provider. That includes purchase records containing the buyer's username, the product title, the amounts, the status, and any discount code. These are records you already hold as the seller, and asking the assistant about them sends them through the routing service described above.

Assistant web search. The assistant can search the web when a question is not answered by your Digiwava data. The search runs through OpenRouter, which uses either the routed model provider's own search or another search provider. The model writes the search query itself, and that query can be based on what you asked and on information the assistant retrieved from your own shop earlier in the same reply.

We also provide a public API (MCP server) that lets third-party AI agents search our product catalog for their users. When an AI agent uses it, we log the search text, the number of results, and the time, and keep that record for 90 days. These records are not linked to a Digiwava account, but they are not always anonymous: a search can itself contain identifying text, and our server logs can record the request's IP address as described under Technical Information.

Connected AI clients. Sellers and administrators can connect a third-party AI client of their own choosing to Digiwava. The client is chosen by the person connecting it: we keep no list of approved clients, and the name a client reports about itself is not verified by us. Connecting requires signing in and approving the exact access the client requested. A seller who approves access to identified sales sends purchase records that identify buyers by username to the client that seller selected, and that client and its own AI provider then process those records under their own terms. Sellers and administrators can revoke a connection at any time in Settings. Revoking disconnects the client. The seller or administrator can approve a new connection later. The client or its AI provider may retain records received from Digiwava. Those records are outside Digiwava's control, and Digiwava cannot delete them. We keep a record of what a connected AI client does on the account, described in Section 4.

Business Transfers

If Digiwava is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal data.

International Transfers

Your data may be processed outside Thailand as part of our global operations. Our primary infrastructure is hosted in Singapore, providing optimal performance for Southeast Asian users. Payment processing occurs through Stripe's global infrastructure, and we use content delivery networks across the ASEAN region for better performance.

For foreign providers that Digiwava contracts with or selects, we use appropriate contractual safeguards under Thai PDPA Section 29 through a binding data processing agreement, recognized standard contractual clauses, or equivalent provider terms. When a transfer is also necessary to perform a contract with you or provide a feature you request, Section 28(3) applies in addition.

We also use encryption in transit and at rest where supported by the provider and share only the information needed for the provider's role.

4. Data Retention

We keep your data only as long as necessary. While your account is active, we maintain your profile information, transaction history, and other account data. Some categories have a fixed lifecycle that applies even while your account remains active:

  • Digiwava Chat history is retained for 90 days for both parties and then permanently deleted. You will only ever see the last 90 days of conversations in your inbox, and older messages are removed nightly. Save copies of anything you may need as support or dispute evidence before it rolls off.
  • AI Assistant conversation text is stored in session storage for the current browser tab and is not copied into an application database conversation record. The tab keeps only the recent conversation window. Digiwava retains content-free turn receipt metadata for 90 days. Separately, our error-monitoring provider retains the model-facing inputs and outputs described in Section 3 for its plan-based span-retention period, currently 30 days, and then deletes them automatically. These diagnostic traces can contain prompts, responses, and model-facing tool data.
  • Completed product-download records come from our storage provider's own request log. Each record notes the account that downloaded, the exact product file, the time, and the IP address, country, and browser information the provider observed. We keep them for 180 days to confirm delivery, investigate a security incident affecting a file, and review suspected account abuse, then delete the whole record. A seller sees only whether you downloaded, when you first and last did, and how many times, never your IP address, country, or browser. We do not submit these records to Stripe.
  • Paid-product payment-attempt records include the server-observed purchase IP for fraud prevention and payment-dispute evidence. The address is removed after 180 days from checkout, while the financial payment record follows its separate legal retention period.
  • Wishlist activity records note when an authenticated buyer saves a product, removes a saved product, or purchases a saved product. They are retained for 90 days to provide sellers and platform administrators with aggregate demand and conversion insights. A seller sees only aggregate counts for their products, not buyer identities or individual wishlists.
  • Connector activity records show which connected AI client acted on an account, who authorized it, which tool it used, when, and whether the action succeeded. They contain no tool inputs, results, or credentials. These records are kept for 365 days so that misuse of a connection can be investigated and so that disputes and support requests about an action taken through a connection can be resolved months after it happened.
  • Original avatar and product preview upload bytes are temporary. They stay private while the server creates the public canonical image. Direct cleanup runs after processing. A delayed cleanup job retains ownership only through the signed-upload safety period when direct deletion does not complete.

After account deletion (whether by you or per ), we retain only the following data for the stated purposes and periods:

  • Financial records, including payment records, issued receipts and tax invoices, and the billing details they contain, for 5 years per Thai tax law
  • Minimal purchase history showing what you bought, when, the transaction status, and whether access remains available, for 5 years to support fulfillment, accounting, refunds, disputes, and legal claims
  • A paid-product payment attempt's purchase IP only until its 180-day expiry from checkout, after which the address is removed from the retained payment record
  • Completed product-download records until their 180-day expiry from the download, after which the whole record including its request details is deleted
  • Seller digital products for 6 months so buyers can access their purchases
  • Account restoration record (original username and sign-in identity, such as an email address or wallet address) for 6 months to provide account recovery at your request
  • Account and security state needed for restoration, including the same account, sign-in credential, verified MFA factors, Digiwava seller tier, and pre-deletion suspension state, for 6 months
  • Any Digiwava Chat messages still within the 90-day window, to support dispute resolution
  • AI Assistant diagnostic traces already held by our error-monitoring provider until their standard 30-day expiry
  • Wishlist activity records still within the 90-day window, with links to the deleted buyer or seller account removed, for aggregate demand and conversion reporting
  • User blocks until final account deletion, so deletion and restoration cannot bypass either party's safety choices
  • Connector activity records for 365 days from the action they describe, so deleting an account cannot erase the record of what a connected AI client did
  • Security and connection logs, which Thai law requires us to keep for at least 90 days; we keep them longer only as needed to protect the platform

Backup copies are purged within 90 days. Data may be retained longer if required for legal proceedings or regulatory investigations.

5. Your Privacy Rights

Under the Thai PDPA, you have rights over your personal data. The law grants you core rights including access, rectification, erasure, data portability, objection, restriction of processing, and withdrawal of consent. Honoring these rights does not require you to provide a reason, and you will never face discrimination or degraded service for exercising them.

Access Your Data

Account settings lets you view and manage your profile, sign-in and security, billing, seller, and support details. Your purchase history is available on the Purchases page, and sellers manage products they create through seller product management. Sellers can also download their complete financial transaction history directly from their Stripe Dashboard.

To receive a portable copy of your data, email privacy@digiwava.com from your registered email address. If your account has no email address (for example, a Web3 wallet account), contact us and we will verify your ownership via in-account confirmation before providing your data. We will provide your personal data in CSV format within 30 days where technically feasible.

Update Your Information

If any of your information is incorrect or outdated, you can update most of it directly in your account settings. For fields you cannot change yourself, contact us and we will assist you promptly.

Delete Your Account

You have the right to delete your account at any time. When you do:

  • Your profile is immediately anonymized (username, email, and personal details)
  • Your username changes to a random identifier
  • Your avatar is permanently removed
  • Reviews you have written are permanently deleted
  • Your votes, follows, support channels, current wishlist, buyer billing defaults, live seller billing profile, seller onboarding state, and unused seller discounts are permanently deleted
  • Links from retained wishlist activity records to your buyer or seller account are removed immediately

We keep a private restoration record of your original username and sign-in identity for 6 months in case you change your mind (see Account Restoration below). After 6 months, this record and your account are permanently deleted.

We retain only the following categories after deletion, for the purposes and periods described in Section 4:

  • Seller digital products remain available to buyers for 6 months
  • Financial records, including payment records, issued receipts and tax invoices, and the billing details they contain, are kept for 5 years to comply with tax law
  • Minimal purchase history showing what you bought, when, the transaction status, and whether access remains available is kept for 5 years to support fulfillment, accounting, refunds, disputes, and legal claims
  • Completed product-download records remain only until the standard 180-day expiry (see Section 4)
  • Account and security state needed for restoration, including the same account, sign-in credential, verified MFA factors, Digiwava seller tier, and pre-deletion suspension state, is kept for 6 months
  • Any Digiwava Chat messages still within the standard 90-day retention window remain restricted to dispute resolution (see Section 4)
  • AI Assistant diagnostic traces already held by our error-monitoring provider remain only until their standard 30-day expiry
  • Deidentified wishlist activity records remain only until the standard 90-day expiry (see Section 4)
  • User blocks remain effective until final account deletion to preserve both parties' safety choices
  • Connector activity records are kept for 365 days from the action they describe (see Section 4)
  • Security and connection logs are kept for at least 90 days as Thai law requires, and longer only as needed to protect the platform

Account Restoration

If your account is deleted (whether by you or by us), you can request restoration within 6 months by emailing privacy@digiwava.com from your registered email address. If your account has no email address (for example, a Web3 wallet account), contact us and we will verify your ownership before restoring your account. Accounts terminated by us for violations of our may not be eligible for restoration. We can restore your username and sign-in identity from the private restoration record. Restoration also returns your private purchase history, any purchase access still available under the product lifecycle, and seller products still within the product-retention window. It also preserves your Digiwava seller tier, verified MFA factors, any pre-deletion account suspension that is still in effect, and existing user blocks. Restoration enables new chat. Messages retained for disputes do not reappear in ordinary chat history and are deleted on the Section 4 schedule. Deidentified wishlist activity is not reattached to the restored account. Reviews, votes, follows, support channels, wishlists, buyer billing defaults, live seller billing profile, seller onboarding state, avatars, and other data deleted at account deletion cannot be recovered. Your Stripe connection is not restored; you must reconnect Stripe, complete seller onboarding again, and re-enter seller billing details before paid products can become eligible for sale again. After 6 months, restoration is no longer possible as account data is permanently deleted.

Withdraw Consent

Where we process your data based on consent (such as optional features or marketing communications), you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal. You can withdraw consent at any time by contacting us at privacy@digiwava.com; promotional emails, if we introduce them, will also include an unsubscribe link.

Object and Restrict Processing

You have the right to object to certain uses of your data, particularly for marketing purposes or based on our legitimate interests. You can also request that we temporarily restrict processing while we investigate concerns or verify accuracy. Contact us to exercise these rights.

6. Security

We protect your personal data with multiple security measures.

How We Protect Your Data

Data sent between your browser and Digiwava is encrypted in transit using HTTPS and TLS. Data stored on Digiwava-managed servers is encrypted at rest using the safeguards supplied by our infrastructure providers. Passwords are stored as one-way hashes rather than retrievable plaintext, so Digiwava cannot read your password. Information kept only in your browser, such as AI Assistant session text, relies on your browser and device security. Our infrastructure is hosted in secure data centers with regular security audits. Access to production systems is strictly limited, requires multi-factor authentication, and administrative actions such as product moderation and account deletion are logged. We work with trusted security partners including Stripe for PCI-compliant payment processing.

Data Breach Response

If a personal data breach is likely to create a risk to your rights and freedoms, we will notify the Office of the Personal Data Protection Committee (PDPC) without undue delay and, where feasible, within 72 hours after becoming aware of it. If the breach is likely to create a high risk to your rights and freedoms, we will also notify you directly without undue delay, explaining what happened, what information was involved, and what steps you should take.

Your Role in Security

You can help keep your account secure by:

  • Using a strong, unique password and considering a password manager
  • Being cautious with unexpected emails claiming to be from us
  • Keeping your browser and operating system updated
  • Enabling two-factor authentication on your email account (used for password recovery)
  • Contacting us promptly if you notice unusual activity

When purchasing digital products, review seller ratings and product descriptions before buying. While we scan uploaded files for malware, we recommend using antivirus software and exercising caution as you would with any files downloaded from the internet.

7. Cookies

We use cookies and similar technologies for authentication, language preference, platform operation, payment security, and fraud prevention. Stripe may set fraud-prevention cookies and collect device and activity signals on Digiwava pages, including before checkout and whether or not you are signed in. Stripe uses these signals for security and fraud prevention, not advertising. Our analytics service does not use cookies. Digiwava does not place cookies for its own advertising, but an embedded YouTube player can set or read cookies and show non-personalized ads under Google's terms.

Blocking authentication cookies prevents sign-in. Blocking Stripe.js prevents checkout from working, while blocking its fraud-prevention cookies can reduce Stripe's ability to detect fraudulent payments. Other third-party security providers, such as Cloudflare, may set essential security cookies. Blocking YouTube cookies can prevent an embedded video from playing as expected.

8. Children's Privacy

Our platform is intended for users aged 13 and older. We don't knowingly collect information from children under 13. If we discover we've collected data from someone under 13, we'll promptly delete their account and personal data, except where retention is required by law (see Section 4).

For users aged 13 to 19, parental consent is required under . Parents or guardians can contact us to request information about their child's account or request deletion. The prohibition on submitting sensitive personal data applies to minors as well. We encourage parental involvement in young users' online activities. Selling on the platform requires connecting a Stripe account, which has its own age requirements (users under 18 need legal guardian approval).

9. Changes to This Policy

We may update this Privacy Policy from time to time. Minor changes like clarifications or formatting improvements will be reflected in the updated date shown at the top of this page. For material changes that significantly affect your rights or how we handle your data, we will notify you via email or platform notification.

The current version will always be available at digiwava.com/privacy.

10. Contact

Digiwava Co., Ltd. is the data controller.

To ask a privacy question or exercise your rights, email privacy@digiwava.com. We verify your identity before acting on a rights request. We respond to these requests within 30 days and explain when an exception prevents us from fulfilling one.

You may also lodge a complaint with Thailand's Personal Data Protection Committee (PDPC)(opens in a new tab).

Terms of Use, Section 4.6
Purchases
Terms of Use
Terms of Use
Terms of Use, Section 8
Terms of Use
Terms of Use, Section 1