Privacy Policy
Last Updated: October 13, 2025
At AoNeeNa, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your personal information when you use our service. This policy complies with Thailand's Personal Data Protection Act (PDPA) and international best practices.
Information We Collect
We collect information you provide directly to us, including:
- Account Information: Name, email, and password (if you register with email)
- Social Media Information: Profile information from Facebook when you choose to log in via Facebook
- Wishlist Content: Wishlists you create, including titles, descriptions, and product links
- Usage Data: How you interact with our service, including pages visited and features used
- Technical Information: IP address, browser type, device information, and session data for security and improvement purposes
- Optional Information: Profile photos and any other information you choose to provide
Legal Basis for Processing
We process your personal data based on:
- Your consent when you create an account and use our service
- Performance of our contract to provide you with wishlist services
- Legitimate interests in improving our service and ensuring security
- Legal obligations we must fulfill
How We Use Your Information
We use the information we collect to:
- Provide and maintain our service
- Improve and develop new features
- Communicate with you about your account and updates
- Detect, prevent, and address technical and security issues
Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your information only:
- With your consent (e.g., when you share a wishlist)
- To comply with legal obligations
- With service providers who help us operate our platform (e.g., hosting, analytics)
Third-Party Services
We use the following third-party services that may process your data:
- Hosting and Infrastructure: For reliable service delivery
- Analytics: To understand how users interact with our service (anonymized where possible)
- Email Services: For account notifications and communications
- Payment Processing: If applicable, for secure payment handling
- Facebook Login: For authentication via Facebook
These providers are contractually required to protect your data and use it only for the purposes we specify.
Facebook Login
When you choose to log in with Facebook, we receive basic profile information from your Facebook account (name, email, profile picture) as permitted by Facebook. We use this information solely to create and manage your account.
Data Retention
We retain your personal data only as long as necessary:
- Active accounts: Data is retained while your account is active
- Inactive accounts: We may delete accounts inactive for more than 2 years after notification
- Legal requirements: Some data may be retained longer to comply with legal obligations
- Upon account deletion: Personal data is permanently deleted within 30 days, except where legally required to retain
Security Measures
We implement appropriate technical and organizational security measures:
- Encryption of data in transit using SSL/TLS
- Strict access controls and authentication
- Regular security monitoring and updates
- Secure data backup and recovery procedures
While we strive to protect your data, no method of transmission over the Internet is 100% secure. Please use strong passwords and protect your account credentials.
Your Rights
You have the right to:
- Access and update your personal information
- Request deletion of your data
- Request a copy of your data
- Restrict or object to certain data processing
PDPA Compliance (Thailand)
As a service operating in Thailand, we comply with the Personal Data Protection Act B.E. 2562 (2019). Thai users have specific rights under PDPA:
- Right to access your personal data
- Right to data portability
- Right to object to data processing
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to lodge a complaint with the Personal Data Protection Committee
Data Deletion
If you wish to delete your account and personal data, please contact us at:
We will process your request within 30 days.
International Data Transfers
Your data may be transferred to and processed in countries outside of Thailand, including servers and service providers in other jurisdictions. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Children's Privacy
Our service is not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13.
Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by law within 72 hours of becoming aware of the breach.
Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
Contact Us & Data Protection Officer
For questions about this Privacy Policy or to exercise your data protection rights, please contact us at:
Email:
[email protected]We aim to respond to all privacy-related inquiries within 7 business days.