Privacy policy (PDPA)
Last updated: 2026-09-06
This policy explains how SupplyProof handles personal data on this website and in the application, in line with Thailand's Personal Data Protection Act B.E. 2562 (PDPA). It covers both people who use the application and supplier contacts whose details an exporter enters into it.
Data controller: Bangkok Solutions Company, Thailand. Contact hi@supplyproof.app. For supplier data entered by an exporter using SupplyProof, the exporter is the data controller and SupplyProof acts as a data processor on their instructions.
1. Personal data we collect
- Account users: name, work email address, a hashed password, role, and sign-in timestamps.
- Supplier contacts: company name, tax identification number, production site address, contact person name, telephone number, LINE ID and email address, entered by the exporter who works with that supplier.
- Documents and questionnaire answers uploaded through a collection link, together with the name of the person who submitted them.
- Activity records: an append-only audit log of who created, edited, uploaded, exported or deleted what, and when.
- Technical data strictly needed to run the service, such as the IP address seen by our hosting provider in its request logs.
2. What we deliberately do not collect
- Copies of individual workers' national identity cards or passports. The questionnaire asks about practices, never for worker identity documents.
- Special category data such as health, religion, biometric or criminal record data.
- Advertising, profiling, behavioural tracking or third-party analytics data. There are no marketing or analytics cookies on this site.
3. Why we use it, and our lawful basis
| Operating the supplier document workspace, storing and organising documents | Performance of a contract with the customer (PDPA s.24(3)) |
| Sending document requests and expiry reminders to supplier contacts | Legitimate interest of the exporter in maintaining a documented supply chain (PDPA s.24(5)) |
| Collecting questionnaire answers and files through a collection link | Consent given by the supplier at the start of the form (PDPA s.19) |
| Keeping an audit log that cannot be edited | Legitimate interest in integrity, and compliance with buyer and audit obligations (PDPA s.24(5)) |
| Taking subscription payments | Performance of a contract (PDPA s.24(3)) |
4. Cookies
This site uses two strictly necessary cookies and nothing else. No consent banner is shown because no optional, advertising or analytics cookies are set.
| sp_session | Keeps you signed in. Signed, HTTP-only, expires after 7 days or when you sign out. |
| sp_lang | Remembers whether you chose Thai or English. Contains only 'th' or 'en' and lasts one year. |
5. Who processes data on our behalf
We use a small number of service providers, each under a data processing agreement, and we do not sell personal data to anyone.
| Vercel | Application hosting and request logs |
| Neon | Database, hosted in Singapore (ap-southeast-1) |
| Cloudflare R2 | Encrypted file storage |
| Stripe | Subscription payments. Card details go directly to Stripe and never reach our servers. |
6. Cross-border transfer
The database is hosted in Singapore, which is the closest available region to Thailand and reduces latency for Thai users. File storage and application hosting may process data in other countries. Where personal data leaves Thailand we rely on the safeguards in PDPA sections 28 and 29, including contractual protections with each provider. Customers with a strict data residency requirement should contact us before entering data.
7. Security
- Uploaded documents are encrypted with AES-256-GCM before they are written to storage, so the stored object is ciphertext.
- Files are never served from a public storage URL. Access goes through a signed link that expires after ten minutes.
- Passwords are stored only as bcrypt hashes and are never recoverable in plain text.
- Every create, edit, upload, export and deletion is written to an append-only audit log that standard users cannot delete.
- No security measure is perfect. If a breach affects your rights we will notify the Personal Data Protection Committee, and you where required, without undue delay.
8. How long we keep data
- Supplier records, documents and questionnaire answers are kept while the exporter's account is active, because audit readiness depends on document history.
- Superseded document versions are kept so that an auditor can see what was held at a point in time.
- When a supplier's data is deleted on request, the files, answers, links and reminders are removed permanently and only a deletion record remains: company name, tax identification number, who requested it, when, and why.
- Audit log entries are retained for the life of the account because they exist to show that records were not altered retroactively.
9. Your rights under the PDPA
Subject to the conditions in the Act, you may exercise the following rights free of charge:
- Access your personal data and request a copy.
- Rectify data that is inaccurate, incomplete or out of date.
- Erase or anonymise your data, including withdrawing consent given on a supplier form.
- Restrict or object to processing, including objecting to reminder messages.
- Receive your data in a machine-readable form, or have it transmitted to another controller.
- Withdraw consent at any time, without affecting processing carried out before the withdrawal.
- Lodge a complaint with the Personal Data Protection Committee of Thailand.
10. Requests about data an exporter entered
If your details were entered by an exporter who uses SupplyProof, that exporter decides how the data is used and is the controller. Send your request to them first. If you contact us instead we will pass your request on and tell you who it went to. An administrator can delete a supplier's data in full from within the application at any time.
11. Changes to this policy
If we change how personal data is handled we will update this page and change the date above. Material changes affecting existing customers will also be sent by email.
We respond to rights requests within 30 days. We may ask for enough information to confirm who you are before acting, so that we do not disclose data to the wrong person.
Contact
- Email: hi@supplyproof.app
- Data controller: Bangkok Solutions Company, Thailand
- Supervisory authority: Personal Data Protection Committee (PDPC), Bangkok