This policy explains how Digiwava Co., Ltd. collects, uses, discloses, and retains personal data under
Thailand's Personal Data Protection Act (PDPA). It applies to anyone who accesses Digiwava. The full policy
follows; here is the short version:
We collect only what we need to run the marketplace:
Account Information
When you create an account, you provide a username (your public identifier on the platform). For sign-in, you
can use an email address (kept private) with a password or a one-time sign-in link we email to you, a
third-party provider such as Google, or a Web3 wallet (Ethereum or Solana). When you use a third-party
provider, that provider shares basic account information with us, which is stored as part of your sign-in
record; the exact details depend on the provider. When you sign in with a Web3 wallet, your public wallet
address is stored and serves as your account identity; an account created this way has no email address unless
you later add one in your settings. We use your email address, where one is present, to create and identify
your account, and do not use the rest. You can optionally add profile enhancements like an avatar, about
section, or shop name to personalize your presence on the platform.
Transaction Information
For buyers, we maintain a private record of your seller product purchases, including what you bought,
when, the transaction status, download history where applicable, and your current wishlist items. We also
record when an
authenticated buyer adds or removes a wishlist item and when a saved item is purchased, as described in
Section 4.
For sellers, we track your digital product listings, sales metrics, and performance data to help you
understand your business.
Reviews you write become public and associated with your username.
Payment Information
We do not receive or store full card numbers, security codes, or payment credentials. When you make a
purchase, you enter those details into Stripe's secure form embedded on our checkout page. They go directly to
Stripe's PCI-compliant servers. Stripe provides us with limited transaction and card metadata, such as the
transaction ID, payment status, payment method type, and the card's last four digits where applicable.
We also store the trusted server-observed IP address when you attempt to pay for a product, together with its
payment-attempt record. We use it only for fraud prevention and payment-dispute evidence, keep it out of buyer
and seller payment views, and remove it after 180 days. If the request does
not reach us through a trusted network proxy, we do not infer an address from forwarding headers.
When a buyer disputes a seller product payment, Digiwava records the dispute so the sale, receipt, and access
state stay accurate, and shows the seller the amount, reason, status, and response deadline. Digiwava does not
assemble, stage, or submit dispute evidence, and never sends your download or payment records to Stripe for a
dispute. The seller responds to the dispute entirely in their own Stripe account.
Stripe also uses cookies and similar technologies when you visit Digiwava to collect your IP address,
identifying information about your browser or device, and activity indicators. Stripe uses this information to
operate and improve its services, including fraud and loss prevention, authentication, and analysis of service
performance. This collection occurs whether or not you are signed in. Stripe does not use its advanced fraud
signals for advertising and retains them for as long as useful for fraud detection and security under its
privacy policy(opens in a new tab) and cookie policy(opens in a new tab).
For sellers, Stripe handles all identity verification, tax documentation, and banking details directly on
their platform. We store only your Stripe account ID. Payouts flow directly from Stripe to your bank account.
We do not hold your funds, but we may request Stripe to pause payouts to your account if we detect suspicious
activity or to comply with Stripe's requirements (see
).
Billing and Invoice Information
The platform generates receipts and tax invoices for purchases. What we collect depends on your role:
Sellers who list paid products provide business details for their receipts: a business name, a tax
identification number (TIN), and optionally a phone number. VAT-registered sellers also provide a business
address and branch code. These details are stored separately from your public profile and appear only on the
receipts and tax invoices issued to your buyers.
Buyers never need to provide billing details to purchase. If you want a full tax invoice, you provide the
name to show on it, a TIN, a billing address, and optional branch details, either at checkout or, for eligible
purchases, later from your page, where you can also correct an invoice that was issued
with wrong details. Full tax invoices are available for purchases from VAT-registered sellers. You can save
these details in your account settings so future forms are prefilled; otherwise we ask each time and store the
details only with that payment.
Technical Information
To keep our platform secure and functioning properly, we automatically collect technical information: your IP
address, information about your browser and device, session data that keeps you signed in, records of the
requests and pages you load, and error and performance reports. This information helps us detect unusual
activity, prevent unauthorized access, and fix problems across different devices.
Platform Visitors
Even if you do not create an account, we collect basic analytics data and technical information about your
browser and device when you visit our platform. This helps us understand how people use our marketplace and
improve the experience for all visitors. Technical information is collected through standard web server logs
and browser technologies used for security and payment-fraud prevention. Our analytics service does not use
cookies or track individual users.
AI Feature Information
When you use the AI Assistant, we collect the prompts and bounded page context you submit. This can include
your conversation and shop records that the seller assistant reads at your request. Your request is sent to a
third-party AI provider to generate the requested output. We also log the model-facing input and generated
output with our error-monitoring provider to diagnose AI performance and failures.
Support and Contact Information
If you contact us through the contact form, you provide a name, an email address, a subject, and a message so
we can respond. We keep your submission as long as necessary to handle and document your inquiry, and email
you send to our contact addresses is retained on the same basis.
Data We Do Not Request
Your account requires only a username and a single sign-in credential, which can be an email address, a
third-party sign-in such as Google, or a Web3 wallet address. If you do not provide them, we cannot create an
account for you; browsing the marketplace does not require an account. Additional profile information (such as
a bio, shop name, avatar, and social links) is entirely optional and only stored if you choose to provide it.
Your public profile has no fields for real names, phone numbers, or physical addresses. Business details
collected for invoicing (see Billing and Invoice Information above) are stored separately and used only for
receipt and tax invoice generation.
We do not ask you to upload government-issued identity documents or precise geolocation data. When sellers
need identity verification to receive payments, Stripe handles it on Stripe's platform, and Digiwava does not
receive the identity documents from Stripe. Do not submit them through profiles, chat, AI prompts, or other
uploads.
Free-text fields and uploads can contain personal data you choose to submit. These fields include profile
descriptions, chat messages, and AI prompts. Digiwava does not intentionally request sensitive personal data
as defined by the Thai PDPA, including health, disability, genetic or biometric data, sexual behavior,
religious or philosophical beliefs, political opinions, racial or ethnic origin, trade union information, or
criminal records. Do not submit sensitive personal data through Digiwava. Because user content can contain
unexpected information, we cannot guarantee that sensitive data is never received or processed. If we identify
it, we may restrict access to or delete it unless its retention or processing is required or permitted by law.
We do not use sensitive data submitted through user content for marketing or profiling.
When you submit an avatar or product preview, the original image can contain hidden metadata such as camera
details, timestamps, or location data. Digiwava keeps signed-upload originals in private temporary storage.
For preview URL imports, Digiwava keeps the downloaded source only in a limited memory buffer. Our server
orients, resizes when needed, and re-encodes every accepted image. This process removes embedded EXIF, XMP,
IPTC, comments, and thumbnails. Only the new canonical image becomes public. We delete temporary originals
after processing or through delayed cleanup after the upload credential is no longer usable.
2. How We Use Your Information
We use your information for specific, legitimate purposes to operate our marketplace. Under the Thai PDPA, we
process your data based on: consent (optional features, promotional emails if introduced), contract
performance (account creation, order fulfillment), legal obligations (tax reporting, lawful requests),
and legitimate interests (security, fraud prevention, service improvements).
To Provide Our Services
Your information enables us to create and manage your account, process orders and deliver digital products,
facilitate communication between buyers and sellers, provide customer support, and generate download links for
your purchases.
To Improve Our Platform
With your information, we can understand how people use our marketplace, identify and fix technical issues,
develop new features based on user needs, and ensure our platform works well across different devices and
browsers.
For Security and Trust
We use your information to protect our platform and users by preventing fraud and unauthorized access,
investigating violations of our , and resolving disputes between buyers and sellers.
This includes monitoring for unusual account activity and maintaining secure backups.
For Marketing and Analytics
We use a privacy-focused analytics service to understand how people use our marketplace. This service does not
use cookies, does not track individual users, and does not collect personal data. We do not currently use
advertising pixels or retargeting technologies. If we add these in the future, we will update this policy and
obtain your consent where required.
To Communicate With You
You will receive essential service emails including sign-in and password reset emails and important updates
about our terms or privacy policy. We do not currently send promotional emails. If we introduce them, we will
ask for your consent first, and every promotional message will include an unsubscribe link.
To Comply With Legal Obligations
We are required to use certain information to comply with legal obligations, including maintaining transaction
records for 5 years per Thai tax law, responding to valid legal requests
from authorities, and enforcing our to protect the platform and community.
3. How We Share Your Information
We share information only when needed to operate the platform, process payments, meet legal obligations, or
protect the service.
We never sell your personal data to third parties. We don't make your purchase history public or share it with
sellers beyond what is necessary for order fulfillment. We won't share your email with third parties for their
marketing purposes.
With Other Users
Certain information is public on our platform, including your username, avatar, any digital products you are
selling, and reviews you have written. When you complete a transaction, sellers can see your username and what
you purchased from them. If you request a full tax invoice, the seller also receives the invoice name, TIN,
billing address, and any branch details needed to issue and retain that invoice. Sellers act as independent
data controllers of the information they receive through a sale and must handle it in accordance with
applicable data protection law.
With Service Providers
We work with trusted service providers to operate our marketplace:
Payment processing, fraud prevention, and disputes: Stripe handles payments, seller verification, and
disputes. Stripe receives transaction and billing information plus IP addresses, device and browser
identifiers, cookie data, and activity indicators to process payments, authenticate users, and detect fraud
and loss. A seller responds to a dispute in their own Stripe account, and Stripe can provide the evidence
the seller submits there to card networks and the buyer's card issuer. Digiwava submits no dispute evidence.
Security and CDN: Cloudflare provides protection against attacks and content delivery, accessing
technical information like IP addresses.
Cloud infrastructure: Our hosting providers store platform data with strict security requirements.
Error monitoring and diagnostics: We use error monitoring services to find and fix technical problems,
investigate security events, and receive feedback you choose to send. These services receive technical
reports such as error details, browser and device information, IP addresses, the page and request involved,
and your account ID when it is part of the report. Our application telemetry strips message content, form
input, cookies, and sensitive request data. The AI Assistant diagnostic traces described below are the
limited exception and include data sent to and received from the model.
Email delivery: An email delivery service sends our service and moderation emails, receiving recipient
email addresses and message content.
Contact and support services: Providers that handle contact forms and business email receive the contact
details and message content you send so we can review and respond to inquiries.
Analytics: We use privacy-focused analytics to understand platform usage (see
Section 1 and Section 2 for details).
Embedded video: Product and review pages can load privacy-enhanced YouTube players. When a player loads,
Google receives technical and usage information such as the page URL, IP address, browser and device
information, and player interactions. Privacy-enhanced mode prevents that view from personalizing the
viewer's YouTube experience, but the player can use cookies and show non-personalized ads under Google's
Privacy Policy(opens in a new tab).
Our primary service providers operate under terms that include data protection commitments.
For Legal Reasons
We may share information when required by law to comply with court orders, report income for tax purposes,
assist law enforcement with valid requests, or protect against fraud and security risks. We review each
request to ensure it is legally valid and only share the minimum information necessary.
With AI Service Providers
AI features on the platform run through OpenRouter, an AI routing service. OpenRouter selects an eligible
model provider for each request and can move that request to another eligible provider, so the provider that
handles any single request is not fixed in advance. The group of eligible downstream providers changes as
OpenRouter adds, removes, or reroutes model endpoints. When you use the AI Assistant, the prompts and context
you submit may be processed by the routed provider so it can generate the requested output. OpenRouter and
its downstream providers have their own privacy policies and may use inputs according to their terms.
Digiwava's storage of Assistant activity is described in Section 4. AI-powered features are
clearly labeled and entirely optional.
Every AI text request carries the same routing conditions: providers that would collect your data or use it
to train models are excluded, and so are providers that cannot handle the complete request.
OpenRouter also sends a copy of every AI Assistant model request and response to our error-monitoring
provider. This can include system instructions, recent conversation text, bounded page context, and, in seller
or administrator flows, model-facing tool calls and the records returned by those tools. We use these traces
to diagnose Assistant errors, performance, and output quality.
Your shop data in the seller assistant. When you ask the seller assistant about your shop, it can read
your own records and include them in the request sent to the routed model provider. That includes purchase
records containing the buyer's username, the product title, the amounts, the status, and any discount code.
These are records you already hold as the seller, and asking the assistant about them sends them through the
routing service described above.
Assistant web search. The assistant can search the web when a question is not answered by your Digiwava
data. The search runs through OpenRouter, which uses either the routed model provider's own search or
another search provider. The model writes the search query itself, and that query can be based on what you
asked and on information the assistant retrieved from your own shop earlier in the same reply.
We also provide a public API (MCP server) that lets third-party AI agents search our product catalog for their
users. When an AI agent uses it, we log the search text, the number of results, and the time, and keep that
record for 90 days. These records are not linked to a Digiwava account, but they are not
always anonymous: a search can itself contain identifying text, and our server logs can record the request's
IP address as described under Technical Information.
Connected AI clients. Sellers and administrators can connect a third-party AI client of their own choosing
to Digiwava. The client is chosen by the person connecting it: we keep no list of approved clients, and the
name a client reports about itself is not verified by us. Connecting requires signing in and approving the
exact access the client requested. A seller who approves access to identified sales sends purchase records
that identify buyers by username to the client that seller selected, and that client and its own AI provider
then process those records under their own terms. Sellers and administrators can revoke a connection at any
time in Settings. Revoking disconnects the client. The seller or administrator can approve a new connection
later. The client or its AI provider may retain records received from Digiwava. Those records are outside
Digiwava's control, and Digiwava cannot delete them. We keep a record of what a connected AI client does on
the account, described in Section 4.
Business Transfers
If Digiwava is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as
part of that transaction. We will notify you of any change in ownership or control of your personal data.
International Transfers
Your data may be processed outside Thailand as part of our global operations. Our primary infrastructure is
hosted in Singapore, providing optimal performance for Southeast Asian users. Payment processing occurs
through Stripe's global infrastructure, and we use content delivery networks across the ASEAN region for
better performance.
For foreign providers that Digiwava contracts with or selects, we use appropriate contractual safeguards
under Thai PDPA Section 29 through a binding data processing agreement, recognized standard contractual
clauses, or equivalent provider terms. When a transfer is also necessary to perform a contract with you or
provide a feature you request, Section 28(3) applies in addition.
We also use encryption in transit and at rest where supported by the provider and share only the information
needed for the provider's role.
4. Data Retention
We keep your data only as long as necessary. While your account is active, we maintain your profile
information, transaction history, and other account data. Some categories have a fixed lifecycle that applies
even while your account remains active:
Digiwava Chat history is retained for 90 days for both parties and then permanently
deleted. You will only ever see the last 90 days of conversations in your inbox, and
older messages are removed nightly. Save copies of anything you may need as support or dispute evidence
before it rolls off.
AI Assistant conversation text is stored in session storage for the current browser tab and is not copied
into an application database conversation record. The tab keeps only the recent conversation window.
Digiwava retains content-free turn receipt metadata for 90 days. Separately, our
error-monitoring provider retains the model-facing inputs
and outputs described in Section 3 for its plan-based span-retention period,
currently 30 days, and then deletes them automatically. These diagnostic traces can contain prompts,
responses, and model-facing tool data.
Completed product-download records come from our storage provider's own request log. Each record notes the
account that downloaded, the exact product file, the time, and the IP address, country, and browser
information the provider observed. We keep them for 180 days to confirm
delivery, investigate a security incident affecting a file, and review suspected account abuse, then delete
the whole record. A seller sees only whether you downloaded, when you first and last did, and how many
times, never your IP address, country, or browser. We do not submit these records to Stripe.
Paid-product payment-attempt records include the server-observed purchase IP for fraud prevention and
payment-dispute evidence. The address is removed after 180 days from
checkout, while the financial payment record follows its separate legal retention period.
Wishlist activity records note when an authenticated buyer saves a product, removes a saved product, or
purchases a saved product. They are retained for 90 days to provide sellers
and platform administrators with aggregate demand and conversion insights. A seller sees only aggregate
counts for their products, not buyer identities or individual wishlists.
Connector activity records show which connected AI client acted on an account, who authorized it, which tool
it used, when, and whether the action succeeded. They contain no tool inputs, results, or credentials. These
records are kept for 365 days so that misuse of a connection can be investigated
and so that disputes and support requests about an action taken through a connection can be resolved months
after it happened.
Original avatar and product preview upload bytes are temporary. They stay private while the server creates
the public canonical image. Direct cleanup runs after processing. A delayed cleanup job retains ownership
only through the signed-upload safety period when direct deletion does not complete.
After account deletion (whether by you or per ), we
retain only the following data for the stated purposes and periods:
Financial records, including payment records, issued receipts and tax invoices, and the billing details they
contain, for 5 years per Thai tax law
Minimal purchase history showing what you bought, when, the transaction status, and whether access remains
available, for 5 years to support fulfillment, accounting, refunds,
disputes, and legal claims
A paid-product payment attempt's purchase IP only until its
180-day expiry from checkout, after which the address is removed from the
retained payment record
Completed product-download records until their 180-day expiry from the
download, after which the whole record including its request details is deleted
Seller digital products for 6 months so buyers can access their purchases
Account restoration record (original username and sign-in identity, such as an email address or wallet
address) for 6 months to provide account recovery at your request
Account and security state needed for restoration, including the same account, sign-in credential, verified
MFA factors, Digiwava seller tier, and pre-deletion suspension state, for
6 months
Any Digiwava Chat messages still within the 90-day window, to support dispute
resolution
AI Assistant diagnostic traces already held by our error-monitoring provider until their standard 30-day
expiry
Wishlist activity records still within the 90-day window, with links to the
deleted buyer or seller account removed, for aggregate demand and conversion reporting
User blocks until final account deletion, so deletion and restoration cannot bypass either party's safety
choices
Connector activity records for 365 days from the action they describe, so deleting
an account cannot erase the record of what a connected AI client did
Security and connection logs, which Thai law requires us to keep for at least 90 days; we keep them longer
only as needed to protect the platform
Backup copies are purged within 90 days. Data may be retained longer if required for legal proceedings or
regulatory investigations.
5. Your Privacy Rights
Under the Thai PDPA, you have rights over your personal data. The law grants you core rights including access,
rectification, erasure, data portability, objection, restriction of processing, and withdrawal of consent.
Honoring these rights does not require you to provide a reason, and you will never face discrimination or
degraded service for exercising them.
Access Your Data
Account settings lets you view and manage your profile, sign-in and security, billing, seller, and support
details. Your purchase history is available on the Purchases page, and sellers manage products they create
through seller product management. Sellers can also download their complete financial transaction history
directly from their Stripe Dashboard.
To receive a portable copy of your data, email
privacy@digiwava.com from your registered email address. If your account has no
email address (for example, a Web3 wallet account), contact us and we will verify your
ownership via in-account confirmation before providing your data. We will provide your personal data in CSV
format within 30 days where technically feasible.
Update Your Information
If any of your information is incorrect or outdated, you can update most of it directly in your account
settings. For fields you cannot change yourself, contact us and we will assist you promptly.
Delete Your Account
You have the right to delete your account at any time. When you do:
Your profile is immediately anonymized (username, email, and personal details)
Your username changes to a random identifier
Your avatar is permanently removed
Reviews you have written are permanently deleted
Your votes, follows, support channels, current wishlist, buyer billing defaults, live seller billing
profile, seller onboarding state, and unused seller discounts are permanently deleted
Links from retained wishlist activity records to your buyer or seller account are removed immediately
We keep a private restoration record of your original username and sign-in identity for
6 months in case you change your mind (see Account Restoration below). After
6 months, this record and your account are permanently deleted.
We retain only the following categories after deletion, for the purposes and periods described in
Section 4:
Seller digital products remain available to buyers for 6 months
Financial records, including payment records, issued receipts and tax invoices, and the billing details they
contain, are kept for 5 years to comply with tax law
Minimal purchase history showing what you bought, when, the transaction status, and whether access remains
available is kept for 5 years to support fulfillment, accounting,
refunds, disputes, and legal claims
Completed product-download records remain only until the standard
180-day expiry (see Section 4)
Account and security state needed for restoration, including the same account, sign-in credential, verified
MFA factors, Digiwava seller tier, and pre-deletion suspension state, is
kept for 6 months
Any Digiwava Chat messages still within the standard 90-day retention window remain
restricted to dispute resolution (see Section 4)
AI Assistant diagnostic traces already held by our error-monitoring provider remain only until their
standard 30-day expiry
Deidentified wishlist activity records remain only until the standard 90-day
expiry (see Section 4)
User blocks remain effective until final account deletion to preserve both parties' safety choices
Connector activity records are kept for 365 days from the action they describe (see
Section 4)
Security and connection logs are kept for at least 90 days as Thai law requires, and longer only as needed
to protect the platform
Account Restoration
If your account is deleted (whether by you or by us), you can request restoration within
6 months by emailing
privacy@digiwava.com from your registered email address. If your account has no
email address (for example, a Web3 wallet account), contact us and we will verify your
ownership before restoring your account. Accounts terminated by us for violations of our
may not be eligible for restoration. We can restore your username and sign-in identity
from the private restoration record. Restoration also returns your private purchase history, any purchase
access still available under the product lifecycle, and seller products still within the product-retention
window. It also preserves your Digiwava seller tier, verified MFA factors, any pre-deletion account suspension
that is still in effect, and existing user blocks. Restoration enables new chat. Messages retained for
disputes do not reappear in ordinary chat history and are deleted on the
Section 4 schedule. Deidentified wishlist activity is not reattached to the restored
account. Reviews, votes, follows, support channels, wishlists, buyer billing defaults, live seller billing
profile, seller onboarding state, avatars, and other data deleted at account deletion cannot be recovered.
Your Stripe connection is not restored; you must reconnect Stripe, complete seller onboarding again, and
re-enter seller billing details before paid products can become eligible for sale again. After
6 months, restoration is no longer possible as account data is permanently
deleted.
Withdraw Consent
Where we process your data based on consent (such as optional features or marketing communications), you have
the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any
processing carried out before the withdrawal. You can withdraw consent at any time by contacting us at
privacy@digiwava.com; promotional emails, if we introduce them, will also
include an unsubscribe link.
Object and Restrict Processing
You have the right to object to certain uses of your data, particularly for marketing purposes or based on our
legitimate interests. You can also request that we temporarily restrict processing while we investigate
concerns or verify accuracy. Contact us to exercise these rights.
6. Security
We protect your personal data with multiple security measures.
How We Protect Your Data
Data sent between your browser and Digiwava is encrypted in transit using HTTPS and TLS. Data stored on
Digiwava-managed servers is encrypted at rest using the safeguards supplied by our infrastructure providers.
Passwords are stored as one-way hashes rather than retrievable plaintext, so Digiwava cannot read your
password. Information kept only in your browser, such as AI Assistant session text, relies on your browser and
device security. Our infrastructure is hosted in secure data centers with regular security audits. Access to
production systems is strictly limited, requires multi-factor authentication, and administrative actions such
as product moderation and account deletion are logged. We work with trusted security partners including
Stripe for PCI-compliant payment processing.
Data Breach Response
If a personal data breach is likely to create a risk to your rights and freedoms, we will notify the Office of
the Personal Data Protection Committee (PDPC) without undue delay and, where feasible, within 72 hours after
becoming aware of it. If the breach is likely to create a high risk to your rights and freedoms, we will also
notify you directly without undue delay, explaining what happened, what information was involved, and what
steps you should take.
Your Role in Security
You can help keep your account secure by:
Using a strong, unique password and considering a password manager
Being cautious with unexpected emails claiming to be from us
Keeping your browser and operating system updated
Enabling two-factor authentication on your email account (used for password recovery)
Contacting us promptly if you notice unusual activity
When purchasing digital products, review seller ratings and product descriptions before buying. While we scan
uploaded files for malware, we recommend using antivirus software and exercising caution as you would with any
files downloaded from the internet.
7. Cookies
We use cookies and similar technologies for authentication, language preference, platform operation, payment
security, and fraud prevention. Stripe may set fraud-prevention cookies and collect device and activity
signals on Digiwava pages, including before checkout and whether or not you are signed in. Stripe uses these
signals for security and fraud prevention, not advertising. Our analytics service does not use cookies.
Digiwava does not place cookies for its own advertising, but an embedded YouTube player can set or read
cookies and show non-personalized ads under Google's terms.
Blocking authentication cookies prevents sign-in. Blocking Stripe.js prevents checkout from working, while
blocking its fraud-prevention cookies can reduce Stripe's ability to detect fraudulent payments. Other
third-party security providers, such as Cloudflare, may set essential security cookies. Blocking YouTube
cookies can prevent an embedded video from playing as expected.
8. Children's Privacy
Our platform is intended for users aged 13 and older. We don't knowingly collect information from children
under 13. If we discover we've collected data from someone under 13, we'll promptly delete their account and
personal data, except where retention is required by law (see Section 4).
For users aged 13 to 19, parental consent is required under .
Parents or guardians can contact us to request information about their child's account or request deletion.
The prohibition on submitting sensitive personal data applies to minors as well. We encourage parental
involvement in young users' online activities. Selling on the platform requires connecting a Stripe account,
which has its own age requirements (users under 18 need legal guardian approval).
9. Changes to This Policy
We may update this Privacy Policy from time to time. Minor changes like clarifications or formatting
improvements will be reflected in the updated date shown at the top of this page. For material changes that
significantly affect your rights or how we handle your data, we will notify you via email or platform
notification.
The current version will always be available at digiwava.com/privacy.
10. Contact
Digiwava Co., Ltd. is the data controller.
To ask a privacy question or exercise your rights, email
privacy@digiwava.com. We verify your identity before acting on a rights
request.
We respond to these requests within 30 days and explain when an exception prevents us from fulfilling one.