Privacy Policy
This Privacy Policy explains how HOLOGACHA Co., Ltd. ("HOLO", "we") collects, uses, shares, and protects your personal data when you use the HOLO platform. We are committed to complying with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and applicable international standards.
1. Who we are
HOLO is operated by HOLOGACHA Co., Ltd., a company incorporated in Thailand. For the purposes of the PDPA, HOLO is the data controller for the personal data described in this Policy.
Data Protection Officer contact: dpo@hologacha.com
2. Information we collect
Account data: email, username, password hash, display name, optional avatar, language preference, referral code.
KYC and seller data (collected only when you complete identity verification): legal name; residential address; mobile phone number; Thai national ID or passport number; ID document and selfie images; bank name, account holder name, account number, and a photograph of your bank book; verification status and reviewer notes.
Shipping data: recipient name, phone number, and shipping address.
Transaction and financial data: order history, Marketplace listings and historical offers, Beam payment-attempt and signed provider evidence, order funding and discount snapshots, vault-ownership transfer records, withdrawal requests, Seller Cash ledger entries, and Promo Credit ledger entries.
Activity data: cards owned, pack openings, opening results, wishlist, achievements unlocked, daily-claim and login streak counters, notifications you receive.
Device and technical data: IP address, browser user agent, approximate location derived from IP, session cookies, language cookie, and aggregate analytics.
Operational error-monitoring data: sanitized exception type, allowlisted stack-frame source locations and line numbers, a coarse route family that redacts every deeper path segment, runtime platform, application release, and UAT or Production environment. Performance timing and span transmission is disabled at the initial rollout. Sentry is configured with `sendDefaultPii: false`; HOLO does not enable Session Replay or intentionally send exception messages, URL queries or hashes, cookies, authorization headers, request/response bodies, or direct customer identifiers through this monitoring contract.
Limited product analytics data: when you enable optional browser analytics, pathname-only page views, session activity, and explicit Buy button events; after an order is fulfilled as paid, a server-side Purchase Completed event containing the internal user ID, order and product identifiers, product type, payment-method category, quantity, item count, amount in THB, and analytics environment.
Customer support data: messages and attachments you send, contact details you choose to provide, and technical or support-session data needed to deliver and reconnect Chatwoot conversations.
3. How we use your information
To create and operate your account, authenticate logins, and provide the Platform's features.
To process Pack purchases, HOLO Singles purchases, Marketplace payment verification and vault ownership transfers, Seller Cash and Promo Credit movements, withdrawals, and shipments.
To verify your identity for KYC and to satisfy our anti-money-laundering, anti-fraud, and consumer-protection obligations.
To initiate Beam-hosted checkout, verify signed Beam payment evidence, and reconcile payment incidents.
To detect, prevent, and investigate fraud, abuse, and security incidents (including pattern analysis across accounts).
To monitor service availability and performance and diagnose operational errors and security incidents using sanitized Sentry telemetry.
To send you transactional notifications (order paid, shipment shipped, withdrawal status, achievement unlocked, etc.) by in-app notice or email.
To send service announcements and, with your consent where required, marketing communications. You may opt out of marketing at any time without affecting transactional notices.
To respond to your support requests and to investigate disputes.
To measure completed purchases, product performance, and revenue using the limited analytics described in this Policy.
To comply with legal obligations and lawful requests from authorities.
4. Legal basis for processing
Under the PDPA we rely on the following lawful bases:
- Contract performance — to provide the services you have requested and to administer your account.
- Legal obligation — for KYC, anti-money-laundering, tax, and consumer-protection compliance.
- Legitimate interest — for fraud prevention, network security, service availability, operational error monitoring, service improvement, and aggregate analytics, balanced against your rights.
- Consent — where required (e.g. optional marketing emails). Consent can be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
5. Sharing and disclosure
We do not sell your personal data. We share data only as needed to operate the Platform or to comply with the law.
- Other users: your username, public profile, marketplace listings, and aggregated pull activity (where you opt in) are visible to other users. Your KYC data, contact details, and balance are not visible to other users.
- Buyers and sellers in a Marketplace transaction: the parties see each other's username and the public listing details. A seller does not receive the buyer's shipping address; any later physical shipment is separately requested by the card owner and fulfilled by HOLO.
- Payment processors: checkout and signed payment evidence required to process an external payment are shared with Beam under its processor terms.
- Shipping carriers: recipient name, phone number, and shipping address are shared with the chosen carrier (Kerry Express, Thailand Post, J&T, etc.) for delivery.
- Analytics provider: HOLO sends optional browser analytics to Amplitude after you enable it and sends limited server-side Purchase Completed events as described in this Policy. The server-side event contains the internal user ID and transaction-measurement fields listed in section 2, but not your email, username, password, OTP, authentication tokens, payment slip, bank details, phone number, or shipping address.
- Operational monitoring provider: Sentry processes sanitized browser and server exceptions on HOLO's instructions so we can detect and diagnose Web reliability and security issues; performance telemetry is disabled at the initial rollout. This is not product analytics or advertising, and it operates independently of the optional Analytics consent choice. Sentry is not intentionally sent dynamic path segments, URL queries or hashes, cookies, authorization headers, request/response bodies, exception messages, or direct customer identifiers under this contract. Data location and retention are governed by HOLO's configured Sentry organization/project settings and Sentry's applicable privacy and data-processing terms.
- Customer support provider: Chatwoot hosts the public live-chat widget and processes messages, attachments, contact details you choose to provide, and technical or support-session data needed to deliver and reconnect the conversation, acting on HOLO's instructions.
- Service providers: cloud hosting, database, email delivery, and SMS providers acting on our instructions under data-processing agreements.
- Legal disclosures: we may disclose data when required by law, court order, lawful regulatory request, or to protect the rights, property, or safety of HOLO, our users, or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to commitments to maintain protections substantially equivalent to this Policy.
6. International data transfers
We primarily host and process data in Thailand or in regions providing adequate protection comparable to the PDPA. Where we transfer data internationally (for example, to cloud service providers outside Thailand), we ensure appropriate safeguards are in place such as standard contractual clauses, the recipient's certification under approved schemes, or your explicit consent where required.
7. How long we keep your data
Account data: while your account is active and for a reasonable period afterwards (typically twenty-four months) to handle disputes and chargebacks, unless a longer retention is legally required.
KYC and AML records: for the period required by applicable Thai anti-money-laundering law (currently a minimum of five years from the end of the customer relationship).
Transaction records (orders, payment verification, ownership transfers, ledger entries, withdrawals): for at least seven years from the date of the transaction, to satisfy tax and accounting obligations.
Marketing preferences: until you withdraw consent or your account is closed.
Customer support correspondence, including Chatwoot conversations: typically for two years after resolution.
Operational Sentry error data: according to HOLO's then-current Sentry organization/project retention configuration and the provider's applicable deletion lifecycle; contact us if you need the current setting.
After applicable retention periods, we delete or anonymise data unless we are legally required to retain it.
8. Your rights under the PDPA
Subject to the conditions and exceptions in the PDPA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to our legal retention obligations.
- Restriction — request that processing of your data be limited in certain circumstances.
- Portability — request a copy of certain data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interest, including for direct marketing.
- Withdraw consent — for processing based on consent, at any time.
- Complain — file a complaint with the Personal Data Protection Committee (PDPC) of Thailand.
To exercise any of these rights, contact dpo@hologacha.com. We will respond within thirty (30) days, extendable as permitted by the PDPA.
9. Security
We protect your data with administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit (HTTPS) for all Platform traffic, password hashing with bcrypt, role-based access controls, server-side rate limiting on sensitive endpoints, audit logging of administrative actions and Seller Cash/Promo Credit movements, and physical access controls at our Bangkok vault.
No method of transmission or storage is perfectly secure. If we become aware of a personal data breach that creates a high risk to your rights, we will notify you and the PDPC in accordance with the PDPA.
10. Cookies and similar technologies
We use essential cookies and similar browser storage for authentication, security, language preferences, checkout flows, and remembering your privacy choice. Essential storage cannot be disabled through HOLO because the Platform cannot operate safely without it.
HOLO does not load the public Chatwoot support widget or write support storage until you click Help. After that request, HOLO may keep the signed conversation identifier in `holo.chatwoot-conversation` local storage for up to 365 days so the conversation can continue across page navigation and return visits. The isolated widget does not receive the parent page path, query string, or URL tokens. HOLO uses this storage for customer service, not product analytics or advertising; clearing it may end browser-side conversation continuity.
Optional Amplitude browser analytics is disabled until you consent. You can reject it on the first notice or later enable, disable, or withdraw consent through Cookie settings in the site footer. Withdrawing consent stops future browser analytics and removes the related browser identifiers and queued-event storage.
Sentry Web error monitoring is strictly necessary operational/security monitoring under our legitimate interests, not optional product analytics; performance telemetry is disabled at the initial rollout. Its browser and server SDKs may initialize regardless of your Analytics choice. Under HOLO's integration contract, Sentry does not set HOLO cookies or use local or session storage, Session Replay is disabled, and sensitive URL/request context is removed before transmission.
The Cookie settings control browser analytics only. Separately, after an order is fulfilled as paid, HOLO sends a limited server-to-server Purchase Completed event to Amplitude for transaction measurement. This event does not read or write cookies, local storage, or session storage and continues when optional browser analytics is rejected or unset.
Our Cookie Policy lists the categories, purposes, providers, and browser-storage periods in more detail.
11. Children
The Platform is not directed to users under the age of 18. We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it.
12. Third-party links
The Platform may link to third-party websites or services we do not control. This Policy does not apply to those sites. We encourage you to review their privacy practices.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified via in-app notice or email at least seven (7) days before they take effect. The "last updated" date at the top of this Policy reflects the most recent version.
14. Contact us
Privacy questions or requests to exercise your rights: dpo@hologacha.com
General support: support@hologacha.com