Privacy Policy
Last Updated: June 2026
This Privacy Policy explains how BoardDee handles personal data under Thailand's Personal Data Protection Act (PDPA). It covers what we collect, why, who processes the data on our behalf, how long we keep it, and how to exercise your rights. For privacy questions or data requests, contact support@boarddee.com.
1. Information we collect
- Account data: email, name, phone number, password hash, language preference.
- Phone verification: SMS OTP records and rate-limit counters used to confirm and protect your phone number.
- Listings: the title, description, photos, category, price, location, and contact preferences you publish.
- Reports and support messages: the content of reports you submit and the messages you exchange with support.
- Technical and security logs: IP address, browser, device type, request timestamps, and abuse-prevention signals (rate-limit triggers, anti-bot challenges).
- Cookies: see the Cookie Policy.
- Payments: payment records for paid features (the charge amount, method, and status) via our payment provider. We do not store full card data on BoardDee.
2. Why we use it
- Account management — sign-in, password reset, language preference.
- Phone verification — to reduce spam and scams and to let buyers reach you on a real Thai number.
- Listing publication — storing, indexing, and showing your listings to viewers.
- Translation — generating the other-language version of your listing so it reaches both Thai and English audiences.
- Moderation — enforcing the Terms of Service and Posting Rules.
- Fraud and abuse prevention — rate limiting, anti-bot challenges, suspicious-activity detection.
- Customer support — answering your messages and resolving issues.
- Legal compliance — responding to lawful requests and protecting our rights and users.
3. Service providers
BoardDee relies on third-party service providers to operate. They process personal data on our behalf, only as needed to provide their service, and subject to their own security and privacy commitments. We work with providers in the following categories:
- Cloud hosting, database & file storage — to run the service and store your account data, listings, and uploaded images securely.
- SMS & email delivery — to send phone-verification codes and transactional notifications (listing alerts, support replies).
- Anti-bot & security — to protect sign-in, posting, and other sensitive forms from automated abuse.
- AI processing — assisted translation between Thai and English, natural-language search query parsing, and optional voice transcription for voice search.
- Payment processing — to process payments for paid features (credit/debit card and PromptPay). We do not store full card data on BoardDee.
We can provide the specific list of providers in each category on request — email support@boarddee.com.
4. Sharing
We do not sell personal data. We share data with the providers listed above strictly to operate the service. We may disclose data when required by Thai law, in response to a lawful request, or to protect rights, safety, and our users — for example to investigate fraud or safety threats.
5. Retention
- Account and listings: retained while your account is active. Listings expire automatically and are removed from the public site at expiration.
- Account deletion: when you delete your account from Dashboard → Profile, we apply a 30-day grace period during which your account is fully recoverable, then permanently delete profile data, listings, avatar, and verification logs.
- Payment records: retained in anonymized form for tax and accounting compliance after account deletion — they no longer reference your identity.
- Security logs: retained for a limited period needed for fraud and abuse investigation.
- Database backups: rotate on a normal schedule; data in older backups expires with rotation.
6. Your rights (PDPA)
Under the PDPA you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete data.
- Deletion — close your account and have your data deleted (subject to the retention rules above).
- Withdraw consent — for processing that is based on consent.
- Object — to certain processing.
- Data portability — receive your data in a machine-readable form.
- Lodge a complaint with the Personal Data Protection Committee (PDPC).
Most actions are self-serve at Dashboard → Profile, including profile updates, data export, and account deletion. For anything else, email support@boarddee.com.
7. Security
We protect your data with encryption in transit, row-level security in the database, rate limiting on sensitive endpoints, and access logs. No system is perfectly secure; if you suspect a security issue, email support@boarddee.com so we can investigate.
8. Children
BoardDee is intended for adults. We do not knowingly collect personal data from children. If you believe a child has created an account, contact support@boarddee.com and we will remove it.
9. Changes
We may update this Privacy Policy. Material changes will be announced on the site or by email; the "Last updated" date at the top of the page tells you when the most recent version was published.
10. Contact
For privacy questions, data-export requests, or to exercise any PDPA right, email support@boarddee.com.