Explore ChillPay’s complete documentation from user guides to API references `designed to help developers and businesses integrate, operate, and grow with confidence.
PraIn Fintech Company Limited (which refers to PraIn Fintech Company Limited, including the products provided by the Company, such as ModernPay and ChillPay, as well as products to be provided in the future) (hereinafter referred to as “the Company”) recognizes the importance of personal data and other information relating to you, the service user, merchants using the Company’s services, and persons involved in the use of the Company’s services (hereinafter referred to as the “Service User”). In order for Service Users to be confident that the Company operates with transparency and accountability in collecting, using, or disclosing your data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (the “Personal Data Protection Law”) and other applicable laws, the Company has prepared this Privacy Policy (the “Policy”) to inform Service Users of the purposes, scope, and manner in which the Company collects, uses, and discloses personal data, as well as accesses and manages information provided by Service Users to the Company, in compliance with the Personal Data Protection Law.
The Company may amend or revise this Privacy Policy in the future. Service Users are therefore advised to check for updates and review this Privacy Policy on a regular basis. Furthermore, Service Users’ personal data will not be collected, disclosed, made widely available, or used for any purpose other than the purposes already notified to Service Users, unless the Company has obtained the Service User’s consent or is otherwise permitted or required to do so by law.
“Personal Data” means any information relating to a natural person which enables the identification of such a person, whether directly or indirectly, but excluding the personal data of a deceased person.
“Sensitive Personal Data” means personal data pertaining to race, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal record, health data, disability, trade union data, genetic data, biometric data (such as fingerprint or facial scans), or any other data that affects the data subject in a similar manner as announced by the Personal Data Protection Committee.
In order to comply with the Personal Data Protection Law, the Company may be required to obtain your consent to collect, use, or disclose your personal data to the Company and/or a person appointed by the Company as a personal data processor, and/or a government agency and/or private entity, in order to comply with the law. This will depend on the service you use, the context of your relationship with the Company, and other relevant considerations affecting the collection of personal data. The categories of data set out below represent only a general framework for the Company’s collection of personal data. The Company will collect the following data of Service Users (“Personal Data”):
(a) Personal information, such as first name, last name, date of birth, place of birth, marital status, photographs, video footage, signature, information appearing on a national identification card or passport, a copy of an identification card, and identification card number, among others.
(b) Contact information, such as address, telephone number, LINE ID, social media contact channels, and place of work, among others.
(c) Security-related information, such as CCTV footage and information identifying a person’s assets, such as a vehicle and its registration number, in the case of entry onto the Company’s premises, among others.
(d) Employment and education information, such as job title, the organization for which you work, educational background, employment history, and training courses completed, among others.
(e) Financial information, such as records of transactions carried out through the ModernPay and ChillPay systems or the Company’s other services, credit card information, bank account information, deposit account information, e-Wallet information, and other information held with banks or financial institutions by the Service User, among others.
(f) Information relating to access to and use of electronic systems connected with the Company, such as email address, IP address, geolocation, browser type, log files, cookies, and in-application chat history, as well as comments or mentions of the Company or the Company’s business on the internet or other channels, among others.
(g) Information you provide when contacting, or participating in any activity with, the Company, including video recordings, audio recordings, comments, satisfaction feedback, and suggestions provided in connection with the Company’s operations or your participation in the Company’s activities, among others.
(h) Information relating to social relationships, such as your political status, holding of political office, or holding a directorship, among others.
(i) Information relating to your use of the Company’s services, or other information specified in the service agreement with the Company, or information necessary for verification and operational purposes.
(j) Information relating to the devices used to access the Company’s services, such as computers, mobile phones, and POS (Point of Sale) terminals, including Unique Device Identifiers and IP addresses used to identify devices connected to a network, information regarding the device’s operating system, mobile network operator, location, and cookies.
(k) Sensitive personal data, such as health data, disability data, biometric data, and data used to assess behaviour, attitude, and aptitude.
With respect to the sensitive personal data described above, the Company will obtain your consent for the collection and processing of such sensitive personal data, unless the Personal Data Protection Law authorizes the collection of sensitive personal data without consent.
Identity Verification: The Company wishes to inform you that where the Company requires a copy of an identity document, such as a national identification card, passport, or other document, which may contain sensitive personal data such as religion or blood type, the Company has no intention of collecting such data. The Company therefore requests that you cross out or otherwise obscure such information. If you fail to do so, the Company shall be deemed to have your permission to conceal such information itself, and the document shall remain fully valid and enforceable in every respect. Where the Company is unable to conceal such information due to certain limitations, the Company confirms that the collection and use of such document is solely for the purpose of identity verification, and the Company has no intention of collecting or using any sensitive personal data appearing in such document.
The Company will collect, use, or disclose the personal data of Service Users on the legal bases and for the purposes set out below:
– Considering registration applications for the use of products provided by the Company, such as ModernPay and ChillPay, including products to be provided in the future;
– Providing assistance, responding to inquiries, handling requests, providing information, or responding to questions regarding the service;
– Developing and improving the quality and efficiency of the service, and providing convenience to Service Users;
– Processing data for the purpose of providing the service, or any other matter necessary to provide the best possible service to Service Users.
Where the Company collects, uses, or discloses personal data for any purpose other than those stated above, the Company will notify the Service User accordingly at a later time. The Company will collect, use, and disclose your personal data upon obtaining your consent, unless the Personal Data Protection Law authorizes the Company to do so without consent, for the legitimate interests of the Company or of another person or juristic person.
In collecting personal data directly from the data subject, and in using or disclosing such personal data, the Company will obtain the data subject’s consent before or at the time of collection, where consent is required by law, and will process the personal data only to the extent necessary to achieve the purposes expressly specified by the Company.
The Company may also collect personal data obtained from sources other than the data subject directly, but only where necessary and by means permitted by law, such as from relevant service providers or public media, among others.
The Company will retain your personal data for as long as is necessary to fulfil the purposes of collecting, using, and disclosing personal data set out in this notice. The criteria used to determine the retention period include the period during which the Company continues to have a relationship with you, and the data may continue to be retained thereafter where required by law, such as under the law on the prevention and suppression of money laundering, or for the purpose of proving or verifying facts in the event of a possible dispute, within the limitation period prescribed by law, for a period not exceeding 10 years.
The Company may need to disclose personal data in the following circumstances:
– To comply with legal provisions or a court order, or where the Company has been notified to investigate a transaction suspected of being fraudulent by a person involved in the provision of the service or a customer;
– Disclosure to employees, staff, directors, and advisors involved in the provision of the service;
– Where the Company has obtained the consent of the data subject, or the data subject has requested such disclosure;
– Disclosure to the Company’s auditors, external examiners, government agencies, assignees of claims, and any other person or juristic person to whom the Company is required to provide personal data in order to comply with the law;
– Disclosure to a juristic person that controls the Company or is controlled by the Company, including companies under common control with the Company, or any other person with whom the Company has a contractual or other legal relationship, including other service providers authorized to carry out any action with respect to the personal data of Service Users, whether within or outside Thailand, such as external service providers, financial institutions, or other business partners of the Company;
– The transferee of a business or undertaking, in the event that the Company undergoes a merger, or transfers or sells assets and/or the whole or part of its business.
Where personal data must be transferred abroad, the Company will strictly comply with the requirements of the Personal Data Protection Law.
As a data subject, you have the following rights under the Personal Data Protection Law:
Where a data subject submits a request to exercise any of the above rights, the Company will process the request within the period prescribed by law. The Company reserves the right, however, to refuse or decline to act on such a request in circumstances permitted by law, such as under the Anti-Money Laundering Act or the regulations of the Bank of Thailand, where the grounds for the request conflict with the requirements of other applicable laws. In such cases, the Company will not be able to delete the relevant data, because applicable laws require the Company, as the recipient or processor of the data, to retain personal data for a period of 10 years.
The Company’s website may use cookies and related technologies to help the website function efficiently, to analyze usage, and to improve your user experience. For further details, please refer to the Company’s Cookie Policy.
The Company acknowledges and recognizes the importance of Service Users’ personal data. The Company has accordingly continuously improved and developed its personal data security systems to keep them aligned with international security standards. The Company will use its best endeavours to comply with this Personal Data Protection Policy, and places strong emphasis on its personnel, including personal data processors engaged by the Company who have access to personal data or duties under the law, maintaining the security of Service Users’ personal data.
Any translation of this Personal Data Protection Policy, into whatever language, is provided solely for your convenience and is not intended to alter this Personal Data Protection Policy in any respect. In the event of any inconsistency between the Thai language version and any version in a language other than Thai, the Thai language version shall prevail.
The Company may consider amending, revising, or changing this Policy as it deems appropriate, and will notify you via its website (https://www.chillpay.co), with the effective date of each amended version indicated. Nevertheless, the Company recommends that you check regularly so as to be aware of any new version of the Policy before disclosing personal data to the Company.
Continued use of the Company’s products or services after a new Policy takes effect shall be deemed acceptance of the terms of the new Policy. If you do not agree with the contents of this Policy, please discontinue use of the service and contact the Company to clarify the relevant facts.
If you have any questions regarding this Privacy Policy, or wish to exercise your rights as a data subject, you may contact the Company as follows:
PraIn Fintech Company Limited
Email: help@chillpay.co
Telephone: 02-107-7788
Business days and hours: Monday – Friday, 8:00 a.m. – 5:00 p.m.
Website: https://www.chillpay.co
The Company will consider your request to exercise your rights in accordance with the criteria and time period prescribed by law.
Effective date: 1 September 2026
Last updated: 1 September 2026
Terms and Conditions for the Electronic Payment System Service of
PraIn Fintech Company Limited
Welcome to the ChillPay electronic payment system service. These terms and conditions (the “Terms”) govern the use of the electronic payment system service for receiving payment for goods and/or services, provided under the trade name “ChillPay” or any other name designated by the Company, by the party using such service (hereinafter referred to as the “Merchant”). The Merchant agrees to be bound by, and to comply with, these Terms and Conditions for the electronic payment system service of PraIn Fintech Company Limited (the “Service Provider” or the “Company”), together with any related documents and conditions applicable to the use of the service as prescribed by the Company, as follows:
The following terms used in these Terms and Conditions shall have the meanings set out below:
“Service Provider” or “the Company” means Phra In Fintech Company Limited.
“Merchant” means the owner and/or operator of a business, or any person having the legal right to sell goods and/or services, who wishes to use the Company’s electronic payment service to receive payment for goods and/or services.
“Customer” means any natural person or juristic person who is a customer and/or user of the Merchant and who makes payment for goods and/or services through the ChillPay channel.
“Electronic Payment Service” means the Company’s service of receiving payment for goods and/or services from Customers on behalf of the Merchant, through the electronic payment methods and channels designated by the Company, which may include the online receipt of payment via website and/or application and/or any other electronic media connected to the Company’s system.
“Transaction” means a payment transaction for goods and/or services carried out through the ChillPay system.
“Business Day” means a day on which commercial banks are normally open for business in Thailand, excluding bank holidays.
“Suspension of Funds” means the temporary suspension of the transfer or payment of funds relating to all or part of a Transaction, for purposes of verification, risk management, compliance with law, an order of a competent authority, or any other case specified in these Terms.
Upon completing the application for, or registration to use, the electronic payment service, the Merchant shall submit the application documents, identity verification documents, and any other information requested by the Company, in order to undergo Customer Due Diligence (“CDD”) and Know Your Customer (“KYC”) verification of the Merchant, including ongoing monitoring of, and due diligence on, the relationship with the Merchant in accordance with the applicable risk level and the criteria prescribed by law or by the regulatory authorities (the “Verification”), and for the purpose of preparing the contract document for signature.
Where the Merchant’s documents and information successfully pass the Verification, the Company will prepare a contract document for the Merchant’s signature, which may be signed either in hard copy or electronically via DocuSign. However, if payment for goods and/or services is received into the electronic payment service system while the application documents and identity verification documents are still under review, the Company may temporarily suspend the transfer of such funds until the Verification and the signing of the contract have been completed. Such Suspension of Funds shall be carried out only to the extent necessary and in accordance with the applicable laws and requirements.
Once the contract between the Company and the Merchant has become fully effective, the Company will transfer the payment received from the Customer for goods and/or services to the Merchant within the next Business Day following the date of payment by the Customer (T+1), except where a system failure, force majeure event, or an event caused by a bank or a payment network service provider occurs, in which case the Company will transfer the funds within not more than the following Business Day.
Where the Merchant’s documents do not pass the Verification, the Merchant acknowledges and agrees that:
(a) the Company may immediately terminate the electronic payment service without prior notice;
(b) the Company, or its coordinator (as the case may be), will notify the Merchant in writing of the outcome of the Verification, through the contact channel provided by the Merchant to the Company; and
(c) the Company will deduct the service fee based on the Merchant’s actual usage before transferring the remaining amount of the payment received from the Customer back to the Merchant within 30 (thirty) Business Days from the date on which the Company notifies the Merchant of the outcome of the Verification under (b) above.
The Merchant further acknowledges and agrees that, in any case whatsoever, in the event of any damage or claim of any kind arising from the use of the electronic payment service, the Merchant agrees to waive any and all such claims, including but not limited to claims for damages or the exercise of any civil or criminal legal action against the Company, whether in whole or in part.
If the documents or information are incomplete or insufficient for the Verification, the Company’s data verification department will notify the relevant department to coordinate with the Merchant in requesting additional application or identity verification documents. Once the Merchant has submitted the additional documents in full, the verification department will proceed with the Verification and notify the Merchant of the outcome again.
However, if the Merchant fails to submit or prepare the additional documents within 15 (fifteen) days from the date of notification by the Company’s coordinating department, the Company reserves the right to cancel and terminate such electronic payment service without prior notice.
The Merchant acknowledges that it has read and carefully understood these Terms and Conditions, including any attachments hereto (if any), and agrees to regularly check the terms and conditions of this service. Should the Merchant have any questions regarding the service, it may contact the Company at 02-107-7788 or by email at help@chillpay.co during the Company’s business days and hours.
The Merchant agrees to use the electronic payment service through the ChillPay system to receive payment for goods and/or services, with the Company’s duties and responsibilities within the scope of the service being as follows:
An application to use the ChillPay service may be made through the channels designated by the Company, which include:
Upon completing the application, the Merchant must submit to the Company its identity verification documents, application documents, and any other information required by the Company, which may be submitted in either hard copy or electronic (soft copy) form, and shall thereafter sign the contract document, which may be signed either in hard copy or electronically via DocuSign.
The Merchant must be a juristic person duly and legally registered, or a natural person who is the owner and/or operator of a business, or a person having the legal right to sell goods and/or services, and who wishes to use the electronic payment service to receive payment for goods/services. Such business must not be of a nature prohibited by law, and, in the case of a business required by law to hold a licence, the Merchant must obtain and maintain such licence or permit throughout the period during which it uses the service. In addition, the business must not be contrary to the Company’s policies.
The Merchant must promptly notify the Company of any change in material information, such as the nature or type of its business, its authorised signatories, its shareholders, its receiving bank account, its licences, or any other information that may affect the Company’s risk assessment or the provision of the service.
The Company has the right to periodically review the Merchant’s information and status, and may request additional documents or information as it deems appropriate and in accordance with the applicable KYC/CDD requirements.
The Merchant agrees to use the Company’s electronic payment service in accordance with the types of payment service prescribed under the Company’s policy.
The Merchant agrees to cooperate in Customer Due Diligence (“CDD”), Know Your Customer (“KYC”) verification, verification of the Ultimate Beneficial Owner, and any other verification required by the Company or the regulatory authorities.
The Company may continuously monitor and review the Merchant’s transactions in order to assess and manage risk, including reviewing any transaction that appears unusual or that gives rise to reasonable grounds for suspicion.
The Merchant agrees that it will not use the ChillPay service to carry out, or to support, any unlawful act, fraud, money laundering, the financing of terrorism, cybercrime, deception of the public, or any other activity designated by the Company or the regulatory authorities as a prohibited activity or as posing an unacceptable risk.
If the Company detects reasonable grounds for suspicion, the Company has the right to conduct further investigation, suspend the Transaction, suspend the transfer of funds, or terminate its business relationship with the Merchant, as it deems appropriate and in accordance with the applicable laws and requirements.
Both parties acknowledge and agree that each party is responsible for its own tax liability under the law arising from its income, at the applicable rate. Where the law requires one party to withhold tax at source, the other party agrees to cooperate in such withholding and to provide the relevant documents as required by law.
Both parties agree to keep confidential all details, information, and documents that they come to know or become aware of, in any manner, as a result of performing their duties or using the service, and undertake not to disclose or make public such information to any third party, or to permit any person to do so, except in the following cases:
provided that each party agrees to take care to ensure that its employees comply strictly with this confidentiality undertaking.
The Company will collect, use, disclose, and/or process the personal data of the Merchant, its directors, authorised persons, contact persons, Customers, and other related individuals in accordance with the law on personal data protection and other applicable laws.
The Merchant agrees that it will ensure that the individuals concerned are notified of the collection, use, or disclosure of their personal data as required by law, and will ensure that there exists a lawful basis or the necessary consent for disclosing such personal data to the Company.
Details regarding the Company’s collection, use, and disclosure of personal data shall be as set out in the Company’s Privacy Policy, published on the website www.chillpay.co.
Where the Company and the Merchant act in the capacity of data controller or data processor differently, depending on the nature of the relevant data-processing activity, each party shall comply with its duties under the law and shall enter into such additional agreements or documents as may be necessary.
The Company has a policy of accepting complaints and resolving problems through the channels designated by the Company. For further information, or to report a malfunction, please contact 02-107-7788 or email help@chillpay.co during the Company’s business days and hours.
The Company reserves the right to improve or amend the service channel, or any content on this website, at any time. In addition, the Company reserves the right to refuse or restrict any person’s access to this website, or access from any Internet Protocol (IP) address, without any obligation to give notice of, or state the reason for, such action.
These Terms and Conditions of service shall be governed by, and construed in accordance with, the laws of Thailand.