Legal
Privacy Policy
Version 2026-07-11 · Last updated: 11 July 2026
This Privacy Policy explains what personal data AppChain™ ("we", "us") collects when you use the Service, why we process it, who we share it with, and the rights you have. It applies alongside our Terms of Service.
This page is maintained by the AppChain™ team. It describes our current data-handling practices; it is not a certification or independent audit. Some processing is provided by our platform providers under a shared-responsibility model as described below.
1. Data Controller
For personal data processed to operate AppChain™, the AppChain™ team acts as data controller. Contact: privacy@appchain.site.
2. Data We Collect
- Account data — name, email, chosen role (brand/supplier/artisan/logistics), company name, preferred language, hashed password (or Google identifier when you sign in with Google), profile display name.
- Content you submit — briefs, supplier capabilities and capacity, commercial terms, sustainability certifications, gallery images, deal messages.
- Consent record — the version of the Terms and Privacy Policy you accepted, the timestamp, and the browser user-agent string.
- Operational logs — technical logs (timestamps, request paths, error traces, email delivery status) required to run and secure the Service.
- Cookies / local storage — a session token so you stay signed in, and minimal preferences (e.g. language). We do not run third-party advertising trackers.
3. How We Use Data
- Provide the smart-matching service between brands and supply-side users.
- Authenticate you and assign the correct role and dashboards.
- Send transactional emails (verification, deal notifications, password reset).
- Protect the platform (rate-limiting, bot detection, abuse investigations).
- Improve the Service based on aggregated, non-identifying usage patterns.
- Comply with legal obligations and enforce our Terms.
4. Legal Bases
We process personal data on the following legal bases: performance of a contract with you (running the Service you signed up for), your consent (e.g. optional marketing messages, acceptance of these documents), legitimate interests (security, product improvement, preventing abuse), and legal obligations (tax, compliance, lawful requests).
5. Sharing
We only share personal data when necessary:
- Counter-parties you choose — when you post a brief or respond to one, the relevant fields are shared with the matched party so you can transact.
- Infrastructure sub-processors — Lovable Cloud (managed Postgres, authentication, storage, edge functions) for hosting your account and content; Google (only if you choose to sign in with Google); transactional email delivery providers used by the platform.
- Law and safety — where we are required by law or need to protect the rights, property or safety of AppChain™, our users, or the public.
We do not sell personal data, and we do not use your private brief or catalogue data to train third-party AI foundation models.
6. International Transfers
Our infrastructure providers may process data in data centres outside Thailand. Where transfers occur, we rely on appropriate safeguards provided by those sub-processors (such as standard contractual clauses).
7. Retention
We keep account and content data for as long as your account is active, and for a limited period afterwards to comply with legal obligations, resolve disputes and enforce our agreements. Consent records (the terms_acceptances entries) are retained for the life of the account plus a reasonable audit window. Backup copies expire on our provider's rolling backup schedule.
8. Your Rights
Subject to applicable law (including Thailand's PDPA and, where relevant, the EU/UK GDPR), you may request to:
- access the personal data we hold about you;
- correct inaccurate data (much of this is self-service in Account settings);
- delete your account and associated personal data;
- export your data in a portable format;
- withdraw consent where processing is based on consent;
- object to or restrict certain processing, and lodge a complaint with your local data-protection authority.
To exercise a right, email privacy@appchain.site from the address on your account. We respond within 30 days.
9. Security
We rely on our platform provider's managed authentication, encrypted transport (HTTPS), encryption at rest for the primary database, row-level security policies scoped to auth.uid(), hashed passwords, leaked-password checks (HIBP), and honeypot bot protection on sign-up. No online service can guarantee absolute security; please choose a strong unique password and enable Google sign-in when possible.
10. Children
AppChain™ is a B2B service and is not directed to children under 18. We do not knowingly collect personal data from children.
11. Changes
When we materially change this policy we bump the version number at the top and notify signed-in users. Where required by law we will re-request acceptance.
12. Contact
Privacy questions or requests: privacy@appchain.site.