The data actually accessed depends on the feature you use, the permissions (scopes) requested, and the permissions you grant on Google, Meta/Facebook, TikTok, LINE, or another platform. We do not request extra permissions merely to “future-proof” access where no corresponding feature exists.
Data governance for HostDrift CRM, CDP, Quotation, POS, Inventory, and other services
HostDrift is a business-data platform that may process significant volumes of personal data. This notice therefore applies to data imported through files/APIs, collected through websites/forms, received from LINE/Facebook/Email, generated by POS/Quotation/Inventory, or unified and segmented in CDP.
- CRM: identity/contact data, leads, customer profiles, notes, activities, messages, purchase/service history, loyalty, and customer journey.
- CDP: identifiers, events, attributes, cookie/device IDs, consent signals, classifications, segments, audiences, scores, and Single Customer View.
- Quotation/POS: buyer/contact data, products/services, invoices/orders/transaction references, payment status, PromptPay/QR information, and user-submitted payment evidence.
- Inventory/Operations: product/SKU, stock movement, branch, cashier/user, and operational data linkable to a person.
- Messaging/Tracking: channel/user IDs, messages, attachments, web events, page views, campaign/source, logs, and timestamps where enabled.
HostDrift follows data-minimisation and purpose-limitation principles: a system's technical ability to store data does not mean all available data should be collected or retained indefinitely.
Clear Data Controller and Data Processor roles
HostDrift acts as Data Controller where HostDrift determines processing purposes and means, such as HostDrift account administration, HostDrift sales contacts, security logs, HostDrift billing, website analytics, or other activities HostDrift independently decides.
HostDrift acts as Data Processor where a business customer determines whose data is collected, what is collected, and why, then places customers, members, leads, employees, buyers, or other people's data into HostDrift for processing according to customer instructions/configuration.
The actual role depends on facts and contract, not product naming alone. A service-specific order form, DPA, or agreement governs the relevant processing where it provides more specific terms.
Responsibilities of customers uploading other people's data
Where the business customer is Data Controller, the customer is directly responsible for the lawfulness of Customer Data and must maintain safeguards appropriate to its processing, including:
- An appropriate legal basis for collecting, using, disclosing, connecting, combining, enriching, profiling, segmenting, and providing data to HostDrift/sub-processors.
- A clear privacy notice describing purposes, data categories, recipients, retention, and data-subject rights.
- Obtaining/recording/managing/withdrawing consent where consent is required and respecting unsubscribe/opt-out/suppression lists.
- Authority to import data from existing CRM, spreadsheets, websites, POS, LINE/Facebook, APIs, or other sources.
- Handling Data Subject Requests and setting retention consistent with purpose and law.
- Configuring internal roles/permissions and preventing unnecessary staff access.
Purchasing or using a CRM/CDP does not make unlawfully obtained data lawful and does not transfer the Data Controller's statutory duties to HostDrift.
Sensitive data, minors, CCTV, and high-risk data
Thailand PDPA Section 26 data—such as racial/ethnic origin, political opinions, religion/philosophy, sexual behaviour, criminal records, health, disability, trade-union data, genetic data, or biometric data—requires a specific lawful condition and heightened safeguards.
Do not place sensitive data into a general-purpose service unless necessary and unless the service/project expressly supports it, the Data Controller has an appropriate lawful condition/consent where required, and suitable safeguards are in place.
For children/minors, the customer is responsible for guardian/consent mechanisms and applicable legal duties. For CCTV, the customer controlling cameras is responsible for placement, signage/privacy notice, legal basis, retention, access, and appropriate use of footage; HostDrift may only be processor/relay/host according to the agreed architecture.
Do not send PINs, CVVs, OTPs, online-banking passwords, private keys, or secrets not required by a supported feature through ordinary forms/channels.
HostDrift commitments when acting as Data Processor
- Process Customer Data according to documented/configured customer instructions and only as necessary to provide the service, unless applicable law requires otherwise.
- Restrict access to personnel/contractors who need it and are subject to confidentiality obligations.
- Apply technical and organisational safeguards appropriate to risk and cloud/on-premise architecture.
- Use sub-processors only as necessary with appropriate data/confidentiality obligations.
- Reasonably assist the Controller with Data Subject Requests, incidents/breaches, DPIAs, or compliance information within the service/agreement.
- Delete or return Customer Data after service termination according to contract/retention requirements unless law requires retention.
- Maintain processing records required of HostDrift as Processor.
HostDrift does not sell Customer Data for independent third-party advertising and does not use identifiable Customer Data to train a general-purpose AI model for purposes unrelated to the service unless clearly agreed/instructed and supported by an appropriate legal basis.
Data breach, incident response, and notification
Where HostDrift is Data Controller and becomes aware of a personal data breach, we will assess risk, mitigate impact, preserve relevant evidence, and notify Thailand's PDPC Office and/or affected individuals where required, including the 72-hour authority-notification timeframe where the PDPA conditions apply.
Where HostDrift is Data Processor, we will notify the relevant Data Controller without undue delay after becoming aware of a breach affecting Customer Data and provide reasonably available information so the Controller can assess and fulfil its own duties. Customers should maintain an incident contact and responsible response team.
Coverage for POS, Inventory, and future HostDrift services
Product names in this notice are illustrative and not limited to products existing on the revision date. If HostDrift adds POS, Inventory, Loyalty, Booking, Helpdesk, Marketing Automation, AI-assisted features, industry systems, or other services that reference this notice, the same Data Governance, Controller/Processor, Security, Retention, Sub-processor, and data-subject-rights principles apply unless a service-specific Privacy Notice/DPA clearly provides additional or different terms.
Scope and data controller
This policy applies to hostdrift.com and to websites, applications, digital tools, forms, account features, and services operated by HostDrift that link to this policy. For these activities, HostDrift may act as a data controller under Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA).
For systems developed or operated for clients, HostDrift may instead act as a data processor/service provider on the client's documented instructions, depending on the project, contract, and actual processing arrangement.
Personal data we may collect
- Identity and contact data: name, email address, phone number, company, role, and information you submit through forms.
- Account and profile data: username, profile photo, email, account/platform identifiers, and information you authorise through social login or OAuth.
- Connected-service data: account, page, channel, content, selected files, calendar items, messages, analytics, or events only where needed for a feature you request and authorise.
- Technical data: IP address, browser, device, operating system, referrer, timestamps, logs, security events, and system usage information.
- Project and transaction data: business requirements, project information, billing details, and records necessary to perform a contract or service request.
Google, Meta/Facebook, TikTok, LINE and other integrations
When you connect an external account, we request only the permissions reasonably required for the feature you choose. The platform normally presents its own authorisation screen before HostDrift receives relevant data or access tokens.
May include Google Sign-In/OAuth and enabled Google or Google Workspace APIs, such as basic profile information, email, account identifiers, or specific data you select and authorise for a visible feature.
HostDrift's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google API user data is not sold and is not used by HostDrift for advertising or unrelated secondary purposes.
Meta / Facebook
May include Facebook Login, Page, Business, or other Meta tools you connect, such as account/page identifiers, permitted profile data, page data, content, insights, or other data covered by the permissions you grant.
Meta Platform Terms apply to Platform Data made available through Meta products.
TikTok
May include Login Kit, Content Posting, Display, or other enabled TikTok APIs, such as TikTok account identifiers, authorised profile data, content/posting information, or analytics within the granted scope.
Use of TikTok developer services remains subject to the TikTok developer terms and policies.
LINE
May include LINE Login, Messaging API, LIFF, or other LINE services, such as LINE user ID, display name, profile image, content a user sends to an Official Account, and events/webhooks necessary for the requested feature.
LINE-derived user data is handled in accordance with the LINE User Data Policy and applicable LINE developer terms.
Where multiple LINE services are operated, LINE-derived user data is not combined across separate services except where LINE policies and applicable notice/consent requirements permit it.
If HostDrift adds a platform or materially changes how connected-service data is used, we will update this policy and provide additional notice or consent where required by law or the applicable platform.
How we use personal data
- Authenticate users and connect accounts they choose to authorise.
- Provide requested features such as sync, publishing, dashboards, automation, messaging, reporting, and workflows.
- Respond to enquiries, provide support, and deliver system-development projects.
- Maintain security, prevent fraud, spam, abuse, and investigate suspicious activity.
- Measure system performance, troubleshoot, and improve services.
- Perform contracts and comply with legal, tax, accounting, regulatory, or lawful authority requirements.
- Conduct marketing or measurement only where an appropriate legal basis and, where required, consent exists.
Legal bases under the PDPA
Depending on the activity, we may rely on consent, performance of a contract or steps requested before entering a contract, legitimate interests, and compliance with legal obligations. If sensitive personal data must be processed, we will rely on an appropriate legal basis and obtain explicit consent where required.
International data transfers
Global providers such as Google, Meta, TikTok, LINE, or cloud infrastructure providers may process or store data outside Thailand. Where cross-border transfer occurs, we will handle the transfer in accordance with the PDPA and use an appropriate transfer mechanism or safeguard where required or permitted by law.
Data retention
We retain personal data only for as long as reasonably necessary for the relevant purpose, the life of a contract/account/connection, legal obligations, security needs, and applicable dispute or limitation periods. When data is no longer required, we delete, destroy, or anonymise it as appropriate.
OAuth/access tokens are retained only as needed to maintain an authorised connection and are revoked or deleted when the connection is removed or no longer needed, subject to any legal requirement to retain particular records.
Security measures
We use reasonable technical and organisational measures such as access controls, credential/token management, encryption where appropriate, security logging, backups, vulnerability management, and contractor controls. No system can guarantee absolute security. If a personal data breach occurs, we will assess and make notifications to the competent authority and affected individuals where required by the PDPA.
Your personal data rights
Subject to the conditions of the PDPA, you may have rights to access and obtain a copy of your data, rectify it, request erasure, restrict processing, object, request data portability, withdraw consent, and lodge a complaint with Thailand's Personal Data Protection Committee/Office. Withdrawal of consent does not affect processing that was lawful before withdrawal.
Data deletion and disconnect requests
You may revoke platform permissions through Google, Meta/Facebook, TikTok, or LINE account settings where the platform provides that control. To delete data retained by HostDrift, submit a request through our Contact page with the subject Data Deletion Request, identify the relevant service/platform, and provide enough information for us to verify the request and locate the relevant records.
- Open the Contact page.
- Select the most relevant enquiry type or Other Inquiry.
- Use the subject Data Deletion Request.
- Identify the connected platform and necessary account details, but never send a password or access token.
We will process valid requests within the period required by applicable law, subject to lawful retention needs for security, contractual obligations, legal claims, or other legal requirements.
Client systems developed by HostDrift
Where a client determines the purposes and means of processing in a system HostDrift develops or operates, the client may be the data controller and HostDrift may act as a processor. That processing should be further governed by the project agreement, data processing agreement (DPA), statement of work, and the client's own privacy notice.
Children and minors
HostDrift's general services are not intentionally designed to collect personal data from children or minors. Where a specific service requires such processing, appropriate consent/guardian mechanisms and safeguards will be applied as required by applicable law.
Policy changes and contact
We may update this policy when our services, applicable law, or platform requirements change. Material changes will be communicated through an appropriate channel. For privacy questions, rights requests, or deletion requests, please use the HostDrift Contact form.
