Legal

Privacy Policy

Version 2026-07-11 · Last updated: 11 July 2026

This Privacy Policy explains what personal data AppChain™ ("we", "us") collects when you use the Service, why we process it, who we share it with, and the rights you have. It applies alongside our Terms of Service.

This page is maintained by the AppChain™ team. It describes our current data-handling practices; it is not a certification or independent audit. Some processing is provided by our platform providers under a shared-responsibility model as described below.

1. Data Controller

For personal data processed to operate AppChain™, the AppChain™ team acts as data controller. Contact: privacy@appchain.site.

2. Data We Collect

3. How We Use Data

4. Legal Bases

We process personal data on the following legal bases: performance of a contract with you (running the Service you signed up for), your consent (e.g. optional marketing messages, acceptance of these documents), legitimate interests (security, product improvement, preventing abuse), and legal obligations (tax, compliance, lawful requests).

5. Sharing

We only share personal data when necessary:

We do not sell personal data, and we do not use your private brief or catalogue data to train third-party AI foundation models.

6. International Transfers

Our infrastructure providers may process data in data centres outside Thailand. Where transfers occur, we rely on appropriate safeguards provided by those sub-processors (such as standard contractual clauses).

7. Retention

We keep account and content data for as long as your account is active, and for a limited period afterwards to comply with legal obligations, resolve disputes and enforce our agreements. Consent records (the terms_acceptances entries) are retained for the life of the account plus a reasonable audit window. Backup copies expire on our provider's rolling backup schedule.

8. Your Rights

Subject to applicable law (including Thailand's PDPA and, where relevant, the EU/UK GDPR), you may request to:

To exercise a right, email privacy@appchain.site from the address on your account. We respond within 30 days.

9. Security

We rely on our platform provider's managed authentication, encrypted transport (HTTPS), encryption at rest for the primary database, row-level security policies scoped to auth.uid(), hashed passwords, leaked-password checks (HIBP), and honeypot bot protection on sign-up. No online service can guarantee absolute security; please choose a strong unique password and enable Google sign-in when possible.

10. Children

AppChain™ is a B2B service and is not directed to children under 18. We do not knowingly collect personal data from children.

11. Changes

When we materially change this policy we bump the version number at the top and notify signed-in users. Where required by law we will re-request acceptance.

12. Contact

Privacy questions or requests: privacy@appchain.site.