Privacy Policy
This Privacy Policy explains how HOLOGACHA Co., Ltd. ("HOLO", "we") collects, uses, shares, and protects your personal data when you use the HOLO platform. We are committed to complying with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and applicable international standards.
1. Who we are
HOLO is operated by HOLOGACHA Co., Ltd., a company incorporated in Thailand. For the purposes of the PDPA, HOLO is the data controller for the personal data described in this Policy.
Data Protection Officer contact: dpo@hologacha.com
2. Information we collect
Account data: email, username, password hash, display name, optional avatar, language preference, referral code.
KYC and seller data (collected only when you complete identity verification): legal name; residential address; mobile phone number; Thai national ID or passport number; ID document and selfie images; bank name, account holder name, account number, and a photograph of your bank book; verification status and reviewer notes.
Shipping data: recipient name, phone number, and shipping address.
Transaction and financial data: order history, Marketplace listings and historical offers, Beam payment-attempt and signed provider evidence, vault-ownership transfer records, withdrawal requests, Seller Balance ledger entries, and historical PromptPay payment-slip images and verification references retained read-only from before the Beam cutover.
Activity data: cards owned, pack openings, opening results, wishlist, achievements unlocked, daily-claim and login streak counters, notifications you receive.
Device and technical data: IP address, browser user agent, approximate location derived from IP, session cookies, language cookie, and aggregate analytics.
Limited product analytics data: when you enable optional browser analytics, pathname-only page views, session activity, and explicit Buy button events; after an order is fulfilled as paid, a server-side Purchase Completed event containing the internal user ID, order and product identifiers, product type, payment-method category, quantity, item count, amount in THB, and analytics environment.
Customer support data: messages you send to us and content you upload for support review.
3. How we use your information
To create and operate your account, authenticate logins, and provide the Platform's features.
To process Pack purchases, HOLO Singles purchases, Marketplace payment verification and vault ownership transfers, Seller Balance movements, withdrawals, and shipments.
To verify your identity for KYC and to satisfy our anti-money-laundering, anti-fraud, and consumer-protection obligations.
To initiate Beam-hosted checkout, verify signed Beam payment evidence, reconcile payment incidents, and preserve historical manual-payment records where legally required.
To detect, prevent, and investigate fraud, abuse, and security incidents (including pattern analysis across accounts).
To send you transactional notifications (order paid, shipment shipped, withdrawal status, achievement unlocked, etc.) by in-app notice or email.
To send service announcements and, with your consent where required, marketing communications. You may opt out of marketing at any time without affecting transactional notices.
To respond to your support requests and to investigate disputes.
To measure completed purchases, product performance, and revenue using the limited analytics described in this Policy.
To comply with legal obligations and lawful requests from authorities.
4. Legal basis for processing
Under the PDPA we rely on the following lawful bases:
- Contract performance — to provide the services you have requested and to administer your account.
- Legal obligation — for KYC, anti-money-laundering, tax, and consumer-protection compliance.
- Legitimate interest — for fraud prevention, network security, service improvement, and aggregate analytics, balanced against your rights.
- Consent — where required (e.g. optional marketing emails). Consent can be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
5. Sharing and disclosure
We do not sell your personal data. We share data only as needed to operate the Platform or to comply with the law.
- Other users: your username, public profile, marketplace listings, and aggregated pull activity (where you opt in) are visible to other users. Your KYC data, contact details, and balance are not visible to other users.
- Buyers and sellers in a Marketplace transaction: the parties see each other's username and the public listing details. A seller does not receive the buyer's shipping address; any later physical shipment is separately requested by the card owner and fulfilled by HOLO.
- Payment processors: checkout and payment evidence required to process an external payment are shared with Beam under its processor terms. HOLO no longer sends new payment slips to a slip-verification provider; historical slips and extracted references remain protected, read-only records under the retention policy below.
- Shipping carriers: recipient name, phone number, and shipping address are shared with the chosen carrier (Kerry Express, Thailand Post, J&T, etc.) for delivery.
- Analytics provider: HOLO sends optional browser analytics to Amplitude after you enable it and sends limited server-side Purchase Completed events as described in this Policy. The server-side event contains the internal user ID and transaction-measurement fields listed in section 2, but not your email, username, password, OTP, authentication tokens, payment slip, bank details, phone number, or shipping address.
- Service providers: cloud hosting, database, email delivery, and SMS providers acting on our instructions under data-processing agreements.
- Legal disclosures: we may disclose data when required by law, court order, lawful regulatory request, or to protect the rights, property, or safety of HOLO, our users, or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to commitments to maintain protections substantially equivalent to this Policy.
6. International data transfers
We primarily host and process data in Thailand or in regions providing adequate protection comparable to the PDPA. Where we transfer data internationally (for example, to cloud service providers outside Thailand), we ensure appropriate safeguards are in place such as standard contractual clauses, the recipient's certification under approved schemes, or your explicit consent where required.
7. How long we keep your data
Account data: while your account is active and for a reasonable period afterwards (typically twenty-four months) to handle disputes and chargebacks, unless a longer retention is legally required.
KYC and AML records: for the period required by applicable Thai anti-money-laundering law (currently a minimum of five years from the end of the customer relationship).
Transaction records (orders, payment verification, ownership transfers, ledger entries, withdrawals): for at least seven years from the date of the transaction, to satisfy tax and accounting obligations.
Historical payment slips collected before the Beam cutover: for at least five years from their original upload, unless a longer legal retention period applies.
Marketing preferences: until you withdraw consent or your account is closed.
Customer support correspondence: typically for two years after resolution.
After applicable retention periods, we delete or anonymise data unless we are legally required to retain it.
8. Your rights under the PDPA
Subject to the conditions and exceptions in the PDPA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to our legal retention obligations.
- Restriction — request that processing of your data be limited in certain circumstances.
- Portability — request a copy of certain data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interest, including for direct marketing.
- Withdraw consent — for processing based on consent, at any time.
- Complain — file a complaint with the Personal Data Protection Committee (PDPC) of Thailand.
To exercise any of these rights, contact dpo@hologacha.com. We will respond within thirty (30) days, extendable as permitted by the PDPA.
9. Security
We protect your data with administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit (HTTPS) for all Platform traffic, password hashing with bcrypt, role-based access controls, server-side rate limiting on sensitive endpoints, audit logging of administrative actions and Seller Balance movements, and physical access controls at our Bangkok vault.
No method of transmission or storage is perfectly secure. If we become aware of a personal data breach that creates a high risk to your rights, we will notify you and the PDPC in accordance with the PDPA.
10. Cookies and similar technologies
We use essential cookies and similar browser storage for authentication, security, language preferences, checkout flows, and remembering your privacy choice. Essential storage cannot be disabled through HOLO because the Platform cannot operate safely without it.
Optional Amplitude browser analytics is disabled until you consent. You can reject it on the first notice or later enable, disable, or withdraw consent through Cookie settings in the site footer. Withdrawing consent stops future browser analytics and removes the related browser identifiers and queued-event storage.
The Cookie settings control browser analytics only. Separately, after an order is fulfilled as paid, HOLO sends a limited server-to-server Purchase Completed event to Amplitude for transaction measurement. This event does not read or write cookies, local storage, or session storage and continues when optional browser analytics is rejected or unset.
Our Cookie Policy lists the categories, purposes, providers, and browser-storage periods in more detail.
11. Children
The Platform is not directed to users under the age of 18. We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it.
12. Third-party links
The Platform may link to third-party websites or services we do not control. This Policy does not apply to those sites. We encourage you to review their privacy practices.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified via in-app notice or email at least seven (7) days before they take effect. The "last updated" date at the top of this Policy reflects the most recent version.
14. Contact us
Privacy questions or requests to exercise your rights: dpo@hologacha.com
General support: support@hologacha.com