Last updated 1 October 2026 · version 2026-10-01
This policy explains what personal data Business Consignment System (“we”) collects, why, who we share it with and your rights under Thailand's Personal Data Protection Act B.E. 2562 (PDPA). The data controller is Haze Buds Sridonchai Co., Ltd (บจก.เฮซ บัดส์ ศรีดอนไชย), 169/1 Sridonchai Road, Chang Klan, Mueng Chiang Mai, Chiang Mai 50100, Thailand (169/1 ถนนศรีดอนไชย ตำบลช้างคลาน อำเภอเมือง เชียงใหม่ 50100) (tax ID 0505568009967). Contact: services.crgroup@gmail.com.
We only collect what the service needs to work. Fields marked optional are never required.
| Data | Why | Basis |
|---|---|---|
| Your name, email address, password (stored hashed, never readable by us), business name | Create and secure your account and your private workspace | Contract |
| Staff you add: name, email, role and permissions | Give your team access with the right permissions | Contract |
| Business details: logo, cover photo, contact email and phone (optional) | Show your business details inside your workspace and on bills you export | Contract |
| Supplier records: name, contact person, phone, notes, photo (all optional except name) | Run consignment: who supplied what and how they are paid | Contract; you confirm you may store this information (see section 6) |
| Stores, products, stock moves, bills, payments, uploaded receipt files | Core service. Receipts you upload may contain personal data of others; upload only what you need | Contract |
| Activity log: which staff member did what and when | Accountability and security inside your workspace | Legitimate interest |
| Subscription status and Stripe customer/subscription IDs | Provide and bill the Pro plan. We never see or store your card number; Stripe does | Contract; legal obligation (tax records) |
| Sign-in cookie and technical logs (IP address, browser, time) kept by our hosts | Keep you signed in, protect against abuse, fix errors | Strictly necessary / legitimate interest |
| Consent record: the date and version of the Terms and Privacy Policy you accepted at sign-up | Prove you agreed | Legitimate interest |
We do not use advertising trackers, analytics scripts, social-media pixels or session-recording tools, and we do not sell personal data. We do not knowingly collect data from children under 18, and do not collect sensitive data (for example ID card numbers, health or bank details) in any form.
They process data only to provide their service to us. We disclose data to authorities only when the law requires it.
Our providers run servers outside Thailand (including India and the United States). We rely on their contractual data-protection commitments for these transfers, as the PDPA allows.
Workspace data is kept while your account is active. When you delete your account we delete workspace data within 30 days, except billing records we must keep for tax purposes (generally 5–7 years) and backups, which roll off within 35 days.
You may ask us to access, copy, correct, delete, restrict or port your personal data, object to processing, and withdraw consent at any time (this does not affect past processing). Email services.crgroup@gmail.com; we answer within 30 days. You may also complain to Thailand's Personal Data Protection Committee.
Suppliers, staff and customers whose details you store are your responsibility: you are the controller of that data and we are your processor. Add only what you need, make sure the person knows, and remove it when it is no longer needed.
Each business has an isolated workspace with row-level access controls, connections are encrypted in transit, passwords are hashed, and only account owners can manage billing. No system is perfectly secure; we will notify affected users and the authorities of a serious breach as the law requires.
We will post updates here and, for material changes, tell you in the app before they apply.