Privacy Policy

What we collect, what we use it for, how long we keep it, and what you can ask us to do with it.

Version 1.0 Effective 07 Aug 2026
On this page
  1. 1. Scope
  2. 2. Data Controller
  3. 3. What We Collect
  4. 4. Where the Data Comes From
  5. 5. Cookies
  6. 6. Disclosure to Third Parties
  7. 7. International Transfers
  8. 8. Retention Periods
  9. 9. Your Rights
  10. 10. What We Cannot Delete, and Why
  11. 11. Security
  12. 12. Children
  13. 13. Complaints
  14. 14. Changes to This Policy
  15. 15. Contact

krutaek.com is a marketplace for collectors of Thai amulets and sacred objects. This document explains what personal data we collect, why, how long we keep it, who can see it, and what rights you have under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).

The Thai version of this policy prevails if there is any discrepancy between language versions.


1. Scope

This policy covers personal data arising from your use of krutaek.com in all three languages (ไทย / English / 简体中文), both the areas you can browse without an account and the areas that require one.

It does not cover third-party websites you reach from links on our site, nor communication that buyers and sellers conduct outside our platform (private messaging apps, phone calls, in-person meetings), which is beyond our control.


2. Data Controller

The data controller is the operator of krutaek.com.

  • Privacy contact: [ติดต่อ: อีเมลบริษัท]
  • Postal address: [ติดต่อ: ที่อยู่บริษัท]
  • Data Protection Officer (DPO): [ติดต่อ: อีเมลบริษัท] — we are assessing whether this service meets the statutory threshold requiring a DPO. If it does, the appointed officer's name and contact details will be published in this section.

3. What We Collect

Each table below states the legal basis under PDPA sections 19 and 24.

3.1 Account data

What Why Legal basis
Email, password (stored as a one-way hash — we cannot read your password) Account creation, sign-in, password recovery Performance of a contract (s.24(3))
Phone number Basic identity verification, transaction alerts, account recovery Performance of a contract (s.24(3))
Display name, avatar, cover image, bio Presenting you to other users on listings and shop pages Performance of a contract (s.24(3))
Province, year of birth, gender, collecting since, specialist categories Profile display and matching listings to interested buyers (optional fields) Consent (s.19) — you can remove these yourself at any time
Language and notification preferences Making the site behave as you configured it Performance of a contract (s.24(3))

3.2 Identity verification (KYC)

What Why Legal basis
Legal name as shown on the document (encrypted) Confirming a seller is a real person Legitimate interest in fraud prevention (s.24(5)) and contract (s.24(3))
National ID / passport number — stored in three forms: encrypted value, a one-way hash used to detect duplicate registrations and match against our blocklist, and a masked value for display (e.g. X-XXXX-XXXXX-12-3) Preventing multiple accounts used to evade a ban, and verifying sellers Legitimate interest (s.24(5))
Document image and selfie-with-document Allowing our reviewers to confirm the document belongs to you Legitimate interest (s.24(5))
Bank account number (encrypted plus one-way hash) Receiving payment and checking the destination account against accounts with a known fraud history Contract (s.24(3)) and fraud prevention (s.24(5))

Before uploading an ID image, please mask anything we do not need — in particular your religion and blood type, which are sensitive data under PDPA section 26. We recommend writing "for krutaek.com identity verification only" plus the date across the image. If you upload without masking, we treat that as no consent for processing those sensitive fields and will not use them.

Never send identity documents through buyer–seller chat. Use the verification page only — it is the sole channel with proper access control and audit logging.

3.3 Who can see your KYC data

This is the most tightly restricted data set on the platform.

  • Other users see nothing — the only thing visible to others is a "verified" badge. No real name, no ID number, no document image.
  • General staff administrators cannot see it either — access to the verification review screens is deliberately excluded from that role.
  • Only staff specifically assigned to identity review (moderators) can access it, and only as far as needed to process each request.
  • Document images are stored on non-public storage and opened through digitally signed links that expire within minutes, so a copied link cannot be reused.
  • Every access is written to our central audit log — who opened whose record and when. That log records the fact of access only; it does not copy the personal data itself.

3.4 Listings, wanted-to-buy posts and item photos

What Why Legal basis
Title, description, price, condition, quantity Publishing your listing so buyers can find it Contract (s.24(3))
Uploaded images plus a perceptual hash of each image Displaying the listing, and detecting re-use of other people's photos in deceptive listings Contract (s.24(3)) and fraud prevention (s.24(5))
Province / area stated in the listing Letting buyers filter by area, and producing aggregate regional statistics Contract (s.24(3))

Anything you write or upload into a listing is public, searchable on our site and potentially indexed by external search engines. Do not put phone numbers, home addresses or other personal details into listing text or images.

3.5 Messaging and community content

What Why Legal basis
Messages and attachments in buyer–seller chat Enabling you to negotiate, and serving as evidence in a dispute Contract (s.24(3))
Questions, answers, comments, reviews and other community content you write Publishing it as you intended Contract (s.24(3))

We do not routinely read your chats. The system separates "see the list of conversations" from "read message contents". General administrators have only the former. Reading content is restricted to assigned staff, occurs only when a report or dispute requires investigation, and every such access is written to the central audit log.

3.6 Trading, auction and preorder activity

What Why Legal basis
Bid history, including the maximum you authorise the system to bid on your behalf Settling auctions correctly and detecting shill bidding Contract (s.24(3)) and fraud prevention (s.24(5))
Preorder reservations, confirmations and cancellations Allocating limited slots in true sequence Contract (s.24(3))
Completed sale outcomes (model, price, date) Computing aggregate reference prices and indices Legitimate interest (s.24(5))

Your maximum bid is confidential — even the seller running the auction cannot see it. Only auction-audit staff can, and each access is logged.

Data feeding the price index is aggregated so that no individual is identifiable — published pages show ranges, trends and volumes, never who sold to whom.

3.7 Invoices, packages and credits

What Why Legal basis
Subscribed package, invoices, credit ledger entries Issuing accounting documents and allowing balances to be audited Contract (s.24(3)) and statutory accounting/tax duties (s.24(6))
Tax invoice details (if you request one) Compliance with tax law Legal obligation (s.24(6))

We do not store your card number or CVV. When online payment is enabled in future, card entry will take place on a licensed payment service provider's system and we will receive only the result and a reference number.

3.8 Technical and security data

What Why Legal basis
IP address — stored as a one-way hash, never the raw address Detecting multi-account registration, abnormal request volume and suspicious sign-ins, without recording your actual location Legitimate interest (s.24(5))
Device data: device fingerprint (hashed), browser/OS type, last-seen time Powering your "signed-in devices" page and alerting you to sign-ins from a new device Legitimate interest (s.24(5))
Login sessions Keeping you signed in while you use the site Contract (s.24(3))
Fraud risk signals derived by the system Screening deceptive behaviour before other users are harmed Legitimate interest (s.24(5))
Central audit log of actions touching money, permissions or personal data Traceability of who did what to which record Legitimate interest (s.24(5)) and legal obligation (s.24(6))

3.9 Usage and notifications

What Why Legal basis
Search terms that returned no results Improving our synonym dictionary so searches succeed more often Legitimate interest (s.24(5))
Items you favourite, follow or watch Showing your lists and notifying you of activity Contract (s.24(3))
In-app and email notifications about transactions Auction results, preorder outcomes, new messages, account security Contract (s.24(3))
Marketing emails News about new releases, events and promotions Consent (s.19) — opt in or out at any time

Transactional and security emails are not marketing and cannot be switched off while your account is active, because they form part of the service.


4. Where the Data Comes From

  1. Directly from you — registration, profile, listings, verification, support contact.
  2. Automatically from your use — the technical data in section 3.8, and cookies.
  3. From other users — for example when someone reviews you or reports a problem with your listing.
  4. From public sources and external providers — for example social sign-in, where the provider passes us your name and email.

5. Cookies

By default this site uses only cookies that are strictly necessary for it to work. Full details — cookie names, purposes, lifetimes and how to manage them — are in our separate Cookie Policy.


6. Disclosure to Third Parties

We do not sell your personal data and do not trade it for third-party marketing purposes.

We disclose only what is necessary, in these cases:

Recipient Data disclosed Reason
Other users of the site Display name, avatar, listings, reviews, ratings, verification status, and messages you send them This is what makes a marketplace work
Infrastructure providers (servers, storage, email delivery, error monitoring) Only what that service requires Keeping the platform running
Payment service providers (when enabled in future) Name, email, amount, transaction reference Processing payments
Shipping providers (when enabled in future) Recipient name, delivery address, phone Delivering goods
SMS / external identity verification providers (when enabled in future) Phone number, or verification outcome Sending verification codes, verifying identity
Law enforcement, courts, regulators As required by lawful order or statute Legal compliance
Legal advisers and auditors Only what their work requires Protecting both parties' legal rights
An acquirer (in a merger or business transfer) Data relating to your account Continuity of service — we will notify you before any transfer

Every external provider that processes data on our behalf is bound by a data processing agreement, may use the data only on our instructions, and may not use it for its own purposes.

The specific providers we use may change over time. You can request the current list via the contact details below.


7. International Transfers

Some infrastructure providers may operate data centres or support teams outside Thailand. Where that happens, we put appropriate safeguards in place as required by PDPA sections 28 and 29 — for example standard contractual clauses, or selecting jurisdictions and providers with an adequate level of protection.


8. Retention Periods

We keep data for as long as needed for the purpose it was collected, or as long as the law requires, whichever is longer.

Data Retention
Account and profile data For as long as the account is active; after closure it enters the deletion/anonymisation process in section 10
Consent records and rights requests 5 years from the date the account was closed, so we can later prove how consent was obtained and how requests were handled
Inactive device records 24 months from last use, then deleted
Fraud risk signals 24 months, then deleted
No-result search history 12 months, then deleted
Data export files we generate for you 7 days from creation, then removed from our servers
Rejected knowledge-base revision content 90 days, then the content is purged (only the record that a revision was proposed and rejected remains)
Published listings, reviews and community content For as long as they remain published; on deletion or account closure they are anonymised per section 10
Buyer–seller chat For as long as the account is active, except conversations tied to a dispute, which are kept until the dispute concludes
Invoices and accounting/tax records As required by accounting and tax law (typically in the 5–7 year range)
Data under a legal hold Until the hold is lifted

Deletion and anonymisation run on scheduled jobs, so there may be a short interval between the due date and actual removal.


9. Your Rights

The PDPA gives you the following rights, and our system supports all of them.

Right What it means Our timeframe
Access / obtain a copy (s.30) See what data we hold about you and receive a copy Within 30 days of the request
Data portability (s.31) Receive your data in a machine-readable format to use elsewhere Within 30 days
Object to processing (s.32) Object to certain uses of your data Within 30 days
Erasure / anonymisation (s.33) Request deletion of your data or closure of your account Within 30 days — see the limits in section 10
Restriction of use (s.34) Have us pause using your data without deleting it Within 30 days
Rectification (s.35–36) Correct data that is wrong or out of date Profile data is editable yourself immediately; anything else within 30 days
Withdraw consent (s.19) Withdraw consent you previously gave, e.g. non-essential cookies or marketing email Self-service toggles take effect immediately; formal withdrawal requests within 30 days

How to exercise your rights

  • Primary channel: sign in and go to My Account → Privacy (/account/privacy). You can submit any of the request types above and track their status on the same page.
  • Alternative channel: email [ติดต่อ: อีเมลบริษัท]

We may ask you to verify your identity first, so that nobody can impersonate you to extract your data or close your account. The 30-day period starts once we have verified the requester. If a request is complex or requests are numerous, we may extend the period and will explain why.

Exercising your rights is free of charge, unless a request is manifestly repetitive or excessive, in which case we will tell you the cost before proceeding.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.


10. What We Cannot Delete, and Why

When you ask us to delete your account we remove or anonymise as much as we can, but some material must remain.

Deleted outright

  • Avatar, bio, preferences and profile data not tied to a transaction
  • Search history
  • Listings with no transaction attached

Anonymised instead of deleted

  • Reviews and ratings you gave others — the author becomes "deleted user", because sellers have a legitimate interest in their own accumulated rating
  • Bid history in closed auctions — retained as a one-way hash so past results remain auditable
  • Community content that others have replied to — detached from your identity

Retained, with legal basis

  • Invoices and accounting/tax records — legal obligation (s.24(6))
  • Data in an ongoing dispute or under a legal hold — establishment or defence of legal claims (s.24(4))
  • Active blocklist entries — legitimate interest in preventing fraud against other users (s.24(5)); every entry has an expiry date and you have the right to appeal
  • Consent and rights-request records — 5 years per section 8, to prove compliance
  • Security audit logs — for the periods in section 8

If any part of your erasure request is refused, we will tell you in writing which part and on what legal basis.


11. Security

Measures currently in place include:

  • All traffic between your browser and our servers is encrypted (HTTPS)
  • Column-level encryption for sensitive fields: legal name, ID number, bank account number
  • Passwords stored as one-way hashes using a memory-hard algorithm, with passwords known from public breaches rejected
  • Two-factor authentication available to users and mandatory for all staff accounts
  • Alerts when your account is accessed from a new device, and a self-service "sign out everywhere" control
  • Staff access split by role, with sensitive personal data walled off from the general administrator role
  • Central audit logging of actions touching money, permissions or personal data
  • Identity documents held on non-public storage, reachable only through short-lived signed links

No system is perfectly secure, so we cannot promise that no incident will ever occur. What we are accountable for is applying appropriate, industry-standard measures and improving them continuously.

In the event of a data breach posing a risk to your rights and freedoms, we will notify the Personal Data Protection Committee's office within the statutory timeframe and notify you directly where the risk is high.

What helps on your side: use a password unique to this site, enable two-factor authentication, never send identity documents through chat, and check your "signed-in devices" page periodically.


12. Children

This service is intended for people aged 20 or over. Anyone younger requires the consent of a parent or legal guardian.

We do not intend to collect data from children under 10. If we find such data was collected without valid consent, we will delete it. Parents may raise this with us at [ติดต่อ: อีเมลบริษัท].


13. Complaints

If you believe we are processing your data unlawfully, please contact us first at [ติดต่อ: อีเมลบริษัท]. We will investigate and respond.

If you remain dissatisfied, you have the right to complain to:

The Office of the Personal Data Protection Committee (PDPC), Thailand Website: pdpc.or.th

Complaining to the PDPC does not affect your right to pursue civil or criminal proceedings.


14. Changes to This Policy

We may revise this policy when the service changes, when the law changes, or when we find the existing wording insufficiently clear.

  • Every version carries a version number and an effective date shown at the top of the document
  • Where a change materially affects your rights, we will notify you by email or on-site notice before the effective date
  • Where a change requires fresh consent, we will ask for it before processing for the new purpose begins
  • The system records which policy version you acknowledged or consented to, so this remains auditable

15. Contact

Privacy matters and rights requests: [ติดต่อ: อีเมลบริษัท] Postal address: [ติดต่อ: ที่อยู่บริษัท] Self-service: My Account → Privacy (/account/privacy)

Privacy contact

privacy@krutaek.com

Takes under a minute. Free.

  • Save pieces you like and find them again later
  • Post what you are looking for and get alerted when it appears
  • Message sellers directly on the site

This site uses cookies

Necessary cookies keep you signed in and let you place bids. Analytics and marketing cookies help us improve the site — you choose, and you can change your mind at any time. Read the cookie policy