PraIn Fintech Company Limited (which refers to PraIn Fintech Company Limited, including the products provided by the Company, such as ModernPay and ChillPay, as well as products to be provided in the future) (hereinafter referred to as “the Company”) recognizes the importance of personal data and other information relating to you, the service user, merchants using the Company’s services, and persons involved in the use of the Company’s services (hereinafter referred to as the “Service User”). In order for Service Users to be confident that the Company operates with transparency and accountability in collecting, using, or disclosing your data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (the “Personal Data Protection Law”) and other applicable laws, the Company has prepared this Privacy Policy (the “Policy”) to inform Service Users of the purposes, scope, and manner in which the Company collects, uses, and discloses personal data, as well as accesses and manages information provided by Service Users to the Company, in compliance with the Personal Data Protection Law.
The Company may amend or revise this Privacy Policy in the future. Service Users are therefore advised to check for updates and review this Privacy Policy on a regular basis. Furthermore, Service Users’ personal data will not be collected, disclosed, made widely available, or used for any purpose other than the purposes already notified to Service Users, unless the Company has obtained the Service User’s consent or is otherwise permitted or required to do so by law.
“Personal Data” means any information relating to a natural person which enables the identification of such a person, whether directly or indirectly, but excluding the personal data of a deceased person.
“Sensitive Personal Data” means personal data pertaining to race, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal record, health data, disability, trade union data, genetic data, biometric data (such as fingerprint or facial scans), or any other data that affects the data subject in a similar manner as announced by the Personal Data Protection Committee.
In order to comply with the Personal Data Protection Law, the Company may be required to obtain your consent to collect, use, or disclose your personal data to the Company and/or a person appointed by the Company as a personal data processor, and/or a government agency and/or private entity, in order to comply with the law. This will depend on the service you use, the context of your relationship with the Company, and other relevant considerations affecting the collection of personal data. The categories of data set out below represent only a general framework for the Company’s collection of personal data. The Company will collect the following data of Service Users (“Personal Data”):
(a) Personal information, such as first name, last name, date of birth, place of birth, marital status, photographs, video footage, signature, information appearing on a national identification card or passport, a copy of an identification card, and identification card number, among others.
(b) Contact information, such as address, telephone number, LINE ID, social media contact channels, and place of work, among others.
(c) Security-related information, such as CCTV footage and information identifying a person’s assets, such as a vehicle and its registration number, in the case of entry onto the Company’s premises, among others.
(d) Employment and education information, such as job title, the organization for which you work, educational background, employment history, and training courses completed, among others.
(e) Financial information, such as records of transactions carried out through the ModernPay and ChillPay systems or the Company’s other services, credit card information, bank account information, deposit account information, e-Wallet information, and other information held with banks or financial institutions by the Service User, among others.
(f) Information relating to access to and use of electronic systems connected with the Company, such as email address, IP address, geolocation, browser type, log files, cookies, and in-application chat history, as well as comments or mentions of the Company or the Company’s business on the internet or other channels, among others.
(g) Information you provide when contacting, or participating in any activity with, the Company, including video recordings, audio recordings, comments, satisfaction feedback, and suggestions provided in connection with the Company’s operations or your participation in the Company’s activities, among others.
(h) Information relating to social relationships, such as your political status, holding of political office, or holding a directorship, among others.
(i) Information relating to your use of the Company’s services, or other information specified in the service agreement with the Company, or information necessary for verification and operational purposes.
(j) Information relating to the devices used to access the Company’s services, such as computers, mobile phones, and POS (Point of Sale) terminals, including Unique Device Identifiers and IP addresses used to identify devices connected to a network, information regarding the device’s operating system, mobile network operator, location, and cookies.
(k) Sensitive personal data, such as health data, disability data, biometric data, and data used to assess behaviour, attitude, and aptitude.
With respect to the sensitive personal data described above, the Company will obtain your consent for the collection and processing of such sensitive personal data, unless the Personal Data Protection Law authorizes the collection of sensitive personal data without consent.
Identity Verification: The Company wishes to inform you that where the Company requires a copy of an identity document, such as a national identification card, passport, or other document, which may contain sensitive personal data such as religion or blood type, the Company has no intention of collecting such data. The Company therefore requests that you cross out or otherwise obscure such information. If you fail to do so, the Company shall be deemed to have your permission to conceal such information itself, and the document shall remain fully valid and enforceable in every respect. Where the Company is unable to conceal such information due to certain limitations, the Company confirms that the collection and use of such document is solely for the purpose of identity verification, and the Company has no intention of collecting or using any sensitive personal data appearing in such document.
The Company will collect, use, or disclose the personal data of Service Users on the legal bases and for the purposes set out below:
– Considering registration applications for the use of products provided by the Company, such as ModernPay and ChillPay, including products to be provided in the future;
– Providing assistance, responding to inquiries, handling requests, providing information, or responding to questions regarding the service;
– Developing and improving the quality and efficiency of the service, and providing convenience to Service Users;
– Processing data for the purpose of providing the service, or any other matter necessary to provide the best possible service to Service Users.
Where the Company collects, uses, or discloses personal data for any purpose other than those stated above, the Company will notify the Service User accordingly at a later time. The Company will collect, use, and disclose your personal data upon obtaining your consent, unless the Personal Data Protection Law authorizes the Company to do so without consent, for the legitimate interests of the Company or of another person or juristic person.
In collecting personal data directly from the data subject, and in using or disclosing such personal data, the Company will obtain the data subject’s consent before or at the time of collection, where consent is required by law, and will process the personal data only to the extent necessary to achieve the purposes expressly specified by the Company.
The Company may also collect personal data obtained from sources other than the data subject directly, but only where necessary and by means permitted by law, such as from relevant service providers or public media, among others.
The Company will retain your personal data for as long as is necessary to fulfil the purposes of collecting, using, and disclosing personal data set out in this notice. The criteria used to determine the retention period include the period during which the Company continues to have a relationship with you, and the data may continue to be retained thereafter where required by law, such as under the law on the prevention and suppression of money laundering, or for the purpose of proving or verifying facts in the event of a possible dispute, within the limitation period prescribed by law, for a period not exceeding 10 years.
The Company may need to disclose personal data in the following circumstances:
– To comply with legal provisions or a court order, or where the Company has been notified to investigate a transaction suspected of being fraudulent by a person involved in the provision of the service or a customer;
– Disclosure to employees, staff, directors, and advisors involved in the provision of the service;
– Where the Company has obtained the consent of the data subject, or the data subject has requested such disclosure;
– Disclosure to the Company’s auditors, external examiners, government agencies, assignees of claims, and any other person or juristic person to whom the Company is required to provide personal data in order to comply with the law;
– Disclosure to a juristic person that controls the Company or is controlled by the Company, including companies under common control with the Company, or any other person with whom the Company has a contractual or other legal relationship, including other service providers authorized to carry out any action with respect to the personal data of Service Users, whether within or outside Thailand, such as external service providers, financial institutions, or other business partners of the Company;
– The transferee of a business or undertaking, in the event that the Company undergoes a merger, or transfers or sells assets and/or the whole or part of its business.
Where personal data must be transferred abroad, the Company will strictly comply with the requirements of the Personal Data Protection Law.
As a data subject, you have the following rights under the Personal Data Protection Law:
Where a data subject submits a request to exercise any of the above rights, the Company will process the request within the period prescribed by law. The Company reserves the right, however, to refuse or decline to act on such a request in circumstances permitted by law, such as under the Anti-Money Laundering Act or the regulations of the Bank of Thailand, where the grounds for the request conflict with the requirements of other applicable laws. In such cases, the Company will not be able to delete the relevant data, because applicable laws require the Company, as the recipient or processor of the data, to retain personal data for a period of 10 years.
The Company’s website may use cookies and related technologies to help the website function efficiently, to analyze usage, and to improve your user experience. For further details, please refer to the Company’s Cookie Policy.
The Company acknowledges and recognizes the importance of Service Users’ personal data. The Company has accordingly continuously improved and developed its personal data security systems to keep them aligned with international security standards. The Company will use its best endeavours to comply with this Personal Data Protection Policy, and places strong emphasis on its personnel, including personal data processors engaged by the Company who have access to personal data or duties under the law, maintaining the security of Service Users’ personal data.
Any translation of this Personal Data Protection Policy, into whatever language, is provided solely for your convenience and is not intended to alter this Personal Data Protection Policy in any respect. In the event of any inconsistency between the Thai language version and any version in a language other than Thai, the Thai language version shall prevail.
The Company may consider amending, revising, or changing this Policy as it deems appropriate, and will notify you via its website (https://www.chillpay.co), with the effective date of each amended version indicated. Nevertheless, the Company recommends that you check regularly so as to be aware of any new version of the Policy before disclosing personal data to the Company.
Continued use of the Company’s products or services after a new Policy takes effect shall be deemed acceptance of the terms of the new Policy. If you do not agree with the contents of this Policy, please discontinue use of the service and contact the Company to clarify the relevant facts.
If you have any questions regarding this Privacy Policy, or wish to exercise your rights as a data subject, you may contact the Company as follows:
PraIn Fintech Company Limited
Email: help@chillpay.co
Telephone: 02-107-7788
Business days and hours: Monday – Friday, 8:00 a.m. – 5:00 p.m.
Website: https://www.chillpay.co
The Company will consider your request to exercise your rights in accordance with the criteria and time period prescribed by law.
Effective date: 1 September 2026
Last updated: 1 September 2026