Privacy Policy
Privacy Policy and your personal data
We collect only what we need to run the service, store it in Thailand, never sell it, and you can see, correct or delete your data.
Last updated 20 September 2026
This policy explains how ThailandHosting (“we”) collects, uses, discloses and protects the personal data of our customers and of visitors to our website, under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA). It forms part of our Terms of Service. The Thai version governs.
For data about the customers and visitors of sites you build on our platform (orders, bookings, form messages and so on), you are the data controller and we only process it on your instructions. See section 3.
1. What we collect
- Account data: name, email, password (stored only as a bcrypt hash; we cannot read it), chosen language, and when you accepted the Terms.
- Company details (company accounts only): the registered name, tax ID, branch and address that go on tax invoices.
- Billing data: top-ups, amounts, VAT, currency, top-up method (PromptPay or Bitcoin) and the proof you send, such as a transfer slip image or a Bitcoin transaction ID, plus your charge and refund history. We hold no card data, because we do not accept cards.
- Usage data: the services you create, their settings, the quota you use, your support tickets, and any documents you attach when we ask you to verify your identity under the Terms.
- Technical data: IP addresses, used to rate-limit sign-in and sign-up (held in memory for a few minutes), and the computer traffic data the law requires us to keep.
- What you send to the AI: your prompts, the business details you describe, and the page content you ask the AI to edit.
- www.thailandhosting.com sets no cookies and runs no third-party tracking or analytics.
2. Why we use it, and the legal basis
- Performing our contract: running your account, publishing your sites and services, charging your wallet and answering tickets.
- Legal obligations: keeping accounting and tax records and computer traffic data, and answering authorities acting under the law.
- Legitimate interests: security, preventing fraud, spam and abuse of the Terms, and fixing problems.
- Consent: only for things we ask about separately, such as news emails; you can withdraw it at any time.
- We do not sell personal data, and we do not use your site content to train AI models.
3. Your customers’ data on your site
Form messages, orders, bookings, and the names, phone numbers, addresses and emails of customers who reach you through your site, as well as your shop-staff accounts, are data for which you are the controller. We process them only to provide the service to you and for no other purpose. You are responsible for giving your own customers your privacy notice, and you can download or delete this data from the Console.
5. Transfers outside Thailand
Your account data, sites, databases and backups are stored in Thailand. The only data that may be processed outside Thailand is what goes to the AI providers, Google Fonts, IndexNow and Git providers listed in section 4, and we use providers with adequate data protection standards as the PDPA requires.
6. How long we keep it
- Your account data and content: for as long as your account is active.
- Deleted sites: removed at once with every version; files no site uses are cleaned up within about an hour.
- Services paused for an unpaid balance: deleted after 30 days paused.
- Database backups: as many as you set (the newest 7 by default); disaster-recovery copies keep the newest 2 per service.
- Billing and tax records: for as long as accounting and tax law requires.
- Computer traffic data: for as long as the law requires.
7. Cookies
The Console uses only the cookies it needs to keep you signed in. There are no advertising or analytics cookies.
th_session: Console sign-in, 7 days.th_shop_team: shop-staff sign-in (Business Apps).th_mail_route: Webmail access, 30 days.
The Console also keeps your choices in your own browser (local storage), such as language, display currency and editor panel sizes.
8. Security
- Passwords are stored as bcrypt hashes and sign-in tokens as SHA-256 hashes.
- Secrets such as Git access tokens are encrypted with AES-256-GCM before they are stored.
- Connections from outside to websites, the Console, mail and databases use HTTPS/TLS 1.2 or later.
- Sign-in and sign-up attempts are rate-limited to stop password guessing.
- You can turn on two-step sign-in with an authenticator app in the Console (recommended). The app secret is encrypted at rest and recovery codes are stored only as hashes.
- Our staff use accounts separate from customers’, with role-based permissions, an IP allowlist and a log of every action.
If a personal data breach puts your rights at risk, we notify the Personal Data Protection Committee office within 72 hours and tell you without undue delay, as the law requires.
9. Your rights
Under the PDPA you have the right to:
- access your personal data and get a copy;
- receive or transfer it in a machine-readable form (you can download it yourself in the Console: your account data as JSON, your site files, and order or booking lists as CSV);
- have it corrected;
- have it deleted or anonymised, including closing your account yourself in the Console once your websites and services are deleted;
- restrict or object to its processing;
- withdraw consent you gave;
- complain to the Personal Data Protection Committee office (PDPC).
Make a request by opening a ticket from Support & refunds in the Console. We answer within 30 days. We may not be able to do everything asked where the law requires us to keep the data, such as tax records.
10. Changes to this policy
When we change this policy we update the date at the top, and we tell you in the Console if the change significantly affects your rights.
11. Contact us
- Personal data requests: open a ticket from Support & refunds in the Console.
- Report illegal content or abuse: [email protected].
Questions about your data?
To get a copy of, correct or delete your personal data, open a ticket in the Console. We answer within 30 days.