PRIVACY POLICY

1. INTRODUCTION
 
1.1. Welcome to the ShopeePay platform run by ShopeePay (Thailand) Co., Ltd and its affiliates and related corporations (individually and collectively, "Company", "we", "us" or "our"). The Company takes its responsibilities under applicable privacy laws and regulations ("Privacy Laws") seriously and is committed to respecting the privacy rights and concerns of all “Users” of our website and mobile application (the “Platform”) (we refer to the Platform and the services we provide as described in our Platform collectively as the "Services"). Users refers to a user who registers for an account with us for use of the Services (“Users”, “you” or “your”). We recognize the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data. This Privacy Policy (“Privacy Policy” or “Policy”) is designed to assist you in understanding how we collect, use, disclose and/or process the personal data you have provided to us and/or possess about you, whether now or in the future, as well as to assist you in making an informed decision before providing us with any of your personal data. Please read this Privacy Policy carefully. If you have any questions regarding this information or our privacy practices, please see the section entitled "Questions, Concerns or Complaints? Contact Us" at the end of this Privacy Policy.
 
1.2. "Personal Data" or "personal data" means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organization has or is likely to have access. Common examples of personal data could include name, identification number and contact information.
 
1.3. By using the Services, registering for an account with us, visiting our Platform, or accessing the Services, you acknowledge and agree that you accept the practices, requirements, and/or policies outlined in this Privacy Policy, and you hereby consent to us collecting, using, disclosing and/or processing your personal data as described herein. IF YOU DO NOT CONSENT TO THE PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY, PLEASE DO NOT USE OUR SERVICES OR ACCESS OUR PLATFORM. If we change our Privacy Policy, we will notify you including by posting those changes or the amended Privacy Policy on our Platform. We reserve the right to amend this Privacy Policy at any time. To the fullest extent permissible under applicable law, your continued use of the Services or Platform, including placing of any orders, shall constitute your acknowledgment and acceptance of the changes made to this Privacy Policy.
 
1.4 This Policy applies in conjunction with other notices, contractual clauses, consent clauses that apply in relation to the collection, storage, use, disclosure and/or processing of your personal data by us and is not intended to override those notices or clauses unless we state expressly otherwise.  
 
1.5 This Policy applies to mobile applications, call center, website, social media features, social networking sites, online communication channels, and other locations where we collect your data.
 
1.6 This Policy applies to all Users and the third party merchants / business partners such as charities, businesses, telecommunications companies, utility companies, etc. (“3P Merchants”) with whom other Users interact or transact via the Services, including via use of any online payment processing services, except where expressly stated otherwise.
 
2. WHEN WILL COMPANY COLLECT PERSONAL DATA?
 
2.1. We will/may collect personal data about you:-
The above does not purport to be exhaustive and sets out some common instances of when personal data about you may be collected.
 
3. WHAT PERSONAL DATA WILL COMPANY COLLECT?
 
3.1. The personal data that Company may collect includes but is not limited to:-
3.2. You agree not to submit any information to us which is inaccurate or misleading, and you agree to inform us of any inaccuracies or changes to such information. We reserve the right at our sole discretion to require further documentation to verify the information provided by you.
 
3.3. If you do not want us to collect the aforementioned information/personal data, you may opt out at any time by notifying our Data Protection Officer in writing about it. Further information on opting out can be found in the section below entitled "How can you opt-out, remove, request access to or modify information you have provided to us?". Note, however, that opting out of us collecting your personal data or withdrawing your consent for us to collect, use or process your personal data may affect your use of the Services.
 
3.4. Your credit card details will not be sold, exchanged, transferred, or given to any other company for any reason whatsoever, without your consent, other than for the express purpose of delivering the service you have requested. This excludes the transfer of your credit card data to our third party payment processing company. Our third party payment processing company stores all of your credit card details (we store none of your credit card data, and the same is transferred directly to their secure storage, without touching our servers)
 
4. COLLECTION OF OTHER DATA
 
4.1 As with most websites and mobile applications, your computer/mobile device sends information which may include personal data about you that gets logged by a web server when you browse websites through our Platform. This typically includes without limitation your device Internet Protocol (IP) address, , computer/mobile device operating system, and browser type, type of mobile device, the characteristics of the mobile device, the unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device, the address of a referring web site (if any), the pages you visit on our website and mobile applications and the times of visit and sometimes a "cookie" (which can be disabled using your browser preferences) to help the Platform remember your last visit. If you are logged in, this information is associated with your personal account. The information is also included in anonymous statistics to allow us to understand how visitors use our Platform.
 
4.2 Our mobile applications may collect precise information about the location of your mobile device using technologies such as GPS, Wi-Fi, etc. We collect, use, disclose and/or process this information for one or more Purposes including, without limitation, location-based services that you request or to deliver relevant content to you based on your location or to allow you to share your location to other Users as part of the services under our mobile applications. For most mobile devices, you are able to withdraw your permission for us to acquire this information on your location through your device settings. If you have questions about how to disable your mobile device's location services, please contact your mobile device service provider or the device manufacturer.
 
4.3 As when you view pages on our website or mobile application, when you watch content and advertising and access other software on our Platform or through the Services, most of the same information is sent to us (including, without limitation, IP Address, operating system, etc.); but, instead of page views, your device sends us information on the content, advertisement viewed and/or software installed by the Services and the Platform and time. 
 
5. COOKIES
 
5.1. We or our authorized service providers and advertising partners may from time to time use "cookies" or other features to allow us or third parties to collect or share information in connection with your use of our Services or Platform. These features help us improve our Platform and the Services we offer, or help us offer new services and features, and/or enable us and our advertising partners serve more relevant content to you, including through remarketing. “Cookies” are identifiers that are stored on your computer or mobile device that record data about computer or mobile device, how and when the Services or Platform are used or visited, by how many people and other activity within our Platform. We may link cookie information to personal data. Cookies also link to information regarding what items you have selected for purchase and web pages you have viewed. This information is used to keep track of your shopping cart, to deliver content specific to your interests, to enable our third party advertising partners to serve advertisements on sites across the internet, and to conduct data analysis and to monitor usage of the Services.
 
5.2. You may refuse the use of cookies by selecting the appropriate settings on your browser or device. However, please note that if you do this you may not be able to use the full functionality of the website visited or the Services.
 
6. HOW DO WE USE THE INFORMATION YOU PROVIDE US?
 
6.1. We may collect, use, disclose and/or process your personal data for one or more of the following purposes:-
6.2. You acknowledge, consent and agree that ShopeePay may access, preserve and disclose your Account information and Content if required to do so by law or pursuant to an order of a court or by any governmental or regulatory authority having jurisdiction over ShopeePay or in a good faith belief that such access preservation or disclosure is reasonably necessary to: (a) comply with legal process; (b) comply with a request from any governmental or regulatory authority having jurisdiction over ShopeePay; (c) enforce the ShopeePay Terms of Service or this Privacy Policy; (d) respond to any threatened or actual claims asserted against ShopeePay or other claim that any Content violates the rights of third parties; (e) respond to your requests for customer service; or (f) protect the rights, property or personal safety of ShopeePay, its users and/or the public.
 
6.3. As the purposes for which we will/may collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of the applicable data without your consent is permitted by the Privacy Laws.
 
7. HOW DOES COMPANY PROTECT AND RETAIN CUSTOMER INFORMATION?
 
7.1 . We implement a variety of security measures and strive to ensure the security of your personal data on our systems. User personal data is contained behind secured networks and is only accessible by a limited number of employees who have special access rights to such systems. However, there can inevitably be no guarantee of absolute security. 
 
7.2. We will retain personal data in accordance with the Privacy Laws and/or other applicable laws. That is, we will destroy or anonymize your personal data as soon as it is reasonable to assume that (i) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (ii) retention is no longer necessary for any legal or business purposes; and (iii) no other legitimate interests warrant further retention of such personal data. If you cease using the Platform, or your permission to use the Platform and/or the Services is terminated or withdrawn, we may continue storing, using and/or disclosing your personal data in accordance with this Privacy Policy and our obligations under the Privacy Laws. Subject to applicable law, we may securely dispose of your personal data without prior notice to you.
 
8. DOES COMPANY DISCLOSE THE INFORMATION IT COLLECTS FROM ITS VISITORS TO OUTSIDE PARTIES?
 
8.1. In conducting our business, we will/may need to disclose your personal data to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties, whether sited in Thailand or outside of Thailand, for one or more of the above-stated Purposes. Such third party service providers, agents and/or affiliates or related corporations and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes. Such third parties include, without limitation:-
8.2. We may share user information, including statistical and demographic information about our Users and information about their use of the Services with advertising partners and third party suppliers of advertisements, remarketing, and/or other programming. 
 
8.3. For the avoidance of doubt, in the event that Privacy Laws or other applicable laws permit an organisation such as us to collect, use or disclose your personal data without your consent, such permission granted by the laws shall continue to apply. Consistent with the foregoing and subject to applicable law, we may use your personal data for recognized legal grounds by relying on one or more legal grounds relevant to the Purposes including to comply with our legal obligations, to perform our contract with you, to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights, for any other interests according to your consent requesting from you from time to time where it is required or where necessary in connection with a legal claim.
 
8.4. Third parties may unlawfully intercept or access personal data transmitted to or contained on the Platform, technologies may malfunction or not work as anticipated, or someone might access, abuse or misuse information through no fault of ours. We will nevertheless deploy reasonable security arrangements to protect your personal data as required by the Privacy Laws; however, there can inevitably be no guarantee of absolute security such as but not limited to when unauthorised disclosure arises from malicious and sophisticated hacking by malcontents through no fault of ours.
 
8.5. As set forth in ShopeePay’s Terms of Service, users in possession of another User’s personal data through the use of the Services (the “Receiving Party”) hereby agree that, they will (i) comply with all applicable personal data protection laws with respect to any such data; (ii) allow the User whose personal data the Receiving Party has collected (the “Disclosing Party”) to remove his or her data so collected from the Receiving Party’s database; and (iii) allow the Disclosing Party to review what information has been collected about them by the Receiving Party, in each case of (ii) and (iii) above, in compliance with and where required by applicable laws.
 
8.6. Notwithstanding anything set forth herein, 3P Merchants in receipt of any other User’s personal data in connection with their use of the Services shall comply with all applicable Privacy Laws and, in respect of any user’s personal data received from the Company, (i) are not permitted to use such user’s personal data except as reasonably necessary to respond to users’ enquiries and to carry out respond to, process, deal with or complete a transaction without the users’ and the Company’s prior written consent; (ii) should refrain from contacting users using such information outside of the Platform; (iii) are not permitted to disclose such user’s personal data to any unauthorized third parties without the user’s and the Company’s prior written consent; (iv) shall employ sufficient security measures to protect each of the Company user’s personal data in their possession and to delete such data as soon as reasonably possible upon completion of the transaction; and (v) to inform the Company’s Personal Data Protection Officer at dpo.th@shopeepay.com in the event of any potential data breach or other loss of such user’s data.
 
9. INFORMATION ON CHILDREN
 
The Services are not intended for children under the age of 20. We do not knowingly collect or maintain any personal data or non-personally-identifiable information from anyone under the age of 20 nor is any part of our Platform or other Services directed to children under the age of 20. As a parent or legal guardian, please do not allow such children under your care to submit personal data to ShopeePay. In the event that personal data of a child under the age of 20 in your care is disclosed to ShopeePay, you hereby consent to the processing of the child’s personal data and accept and agree to be bound by this Policy on behalf of such child. We will close any accounts used exclusively by such children and will remove and/or delete any personal data we believe was submitted without parental consent by any child under the age of 20.
 
10. INFORMATION COLLECTED BY THIRD PARTIES
 
10.1. Our Platform uses third party analytics services (“3P Analytics Services”), including but not limited to Google Analytics, a web analytics service provided by Google, Inc.. 3P Analytics Services uses cookies, which are text files placed on your computer/mobile device, to help the Platform analyse how Users use the Platform. The information generated by the cookie about your use of the Platform (including your IP address) will be transmitted to and stored by 3P Analytics Services on servers in countries including but not limited to the United States. 3P Analytics Services will use this information for the purpose of evaluating your use of the Platform, compiling reports on Platform activity for Platform operators and providing other services relating to Platform activity and Internet usage. 3P Analytics Services may also transfer this information to third parties where required to do so by law, or where such third parties process the information on the behalf of 3P Analytics Services. 3P Analytics Services will not associate your IP address with any other data held by 3P Analytics Services.
 
10.2. We, and third parties, may from time to time make software applications downloads available for your use via the Platform or through the Services. These applications may separately access, and allow a third party to view, your identifiable information, such as your name, your User ID, your  device’s IP Address or other information such as any cookies that you may previously have installed or that were installed for you by a third party software application or website. Additionally, these applications may ask you to provide additional information directly to third parties. Third party products or services provided through these applications are not owned or controlled by Company. You are encouraged to read the terms and other policies published by such third parties on their websites or otherwise.
 
11. DISCLAIMER REGARDING SECURITY AND THIRD PARTY SITES
 
11.1. WE DO NOT GUARANTEE THE SECURITY OF PERSONAL DATA AND/OR OTHER INFORMATION THAT YOU PROVIDE ON THIRD PARTY SITES. We do implement a variety of security measures to maintain the safety of your personal data that is in our possession or under our control. Your personal data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the personal data confidential. When you place orders or access your personal data, we offer the use of a secure server. All personal data or sensitive information you supply is encrypted into our databases to be only accessed as stated above.
 
11.2. In an attempt to provide you with increased value, we may choose various third party websites to link to, and frame within, the Platform. We may also participate in co-branding and other relationships to offer e-commerce and other services and features to our visitors. These linked sites have separate and independent privacy policies as well as security arrangements. Even if the third party is affiliated with us, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of us. Data collected by our co-brand partners or third party websites (even if offered on or through our Platform) may not be received by us.
 
We therefore have no responsibility or liability for the content, security arrangements (or lack thereof) and activities of these linked sites. These linked sites are only for your convenience and you therefore access them at your own risk. Nonetheless, we seek to protect the integrity of our Platform and the links placed upon each of them and therefore welcome any feedback about these linked sites (including, without limitation, if a specific link does not work).
 
12. WILL COMPANY TRANSFER YOUR INFORMATION OVERSEAS?
 
Your personal data and/or information may be transferred to, stored or processed outside of your country. In most cases, your personal data will be processed in Thailand, where our servers are located. Company will not transfer your information overseas unless the following:-
 
(a) such transfer is in accordance with Privacy Laws; or
(b) your consent is obtained by us; or
(c) such transfer is required under the agreement entered into between you and Company; or
(d) such transfer is made in favour of you and your consent cannot be obtained at the time of transfer.
 
13. HOW CAN YOU OPT-OUT, WITHDRAW, REQUEST ACCESS TO OR MODIFY INFORMATION YOU HAVE PROVIDED TO US?
 
13.1. Withdrawing Consent
 
13.1.1 You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by sending an email to our Personal Data Protection Officer at dpo.th@shopeepay.com , and we will process such requests in accordance with this Privacy Policy and our obligations under the Privacy Laws and other applicable law. However, your withdrawal of consent may mean that we will not be able to continue providing the Services to you and we may need to terminate your existing relationship and/or the contract you have with us.
 
13.1.2 Once we have your clear withdrawal instructions and verified your identity, we will process your request for withdrawal of consent in accordance with this Privacy Policy and our obligations under the Privacy Laws and other applicable laws, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request. If we are unable to verify your identity or understand your instructions, we will liaise with you to understand your request.
 
13.1.3 However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, it may mean that we will not be able to continue providing the Services to you, we may need to terminate your existing relationship and/or the contract you have with us, etc., as the case may be, which we will inform you of.
 
13.2. Requesting Access and/or Correction of Personal Data
 
13.2.1 If you have an account with us, you may personally access and/or correct your personal data currently in our possession or control through the Account Settings page on the Platform. If you do not have an account with us, you may request to access and/or correct your personal data currently in our possession or control by submitting a written request to us. We will need enough information from you in order to ascertain your identity as well as the nature of your request so as to be able to deal with your request. Hence, please submit your written request by sending an email to our Personal Data Protection Officer at dpo.th@shopeepay.com.
 
13.2.2 For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days (or, if you are resident in Malaysia, 21 days). Where we are unable to respond to you within the said 30 days (or, if you are resident in Malaysia, 21 days), we will notify you of the soonest possible time within which we can provide you with the information requested. Note that Privacy Laws may exempt certain types of personal data from being subject to your access request.
 
13.2.3 For a request to correct personal data, once we have sufficient information from you to deal with the request, we will:-
 
(a) correct your personal data within 30 days (or, if you are resident in Malaysia, 21 days). Where we are unable to do so within the said period, we will notify you of the soonest practicable time within which we can make the correction. Note that Privacy Laws may exempt certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request; and

(b) we will send the corrected personal data to every other organization to which the personal data was disclosed by us within a year before the date the correction was made, unless that other organization does not need the corrected personal data for any legal or business purpose.
 
13.2.4 Notwithstanding sub-paragraph (b) immediately above, we may, if you so request, send the corrected personal data only to specific organizations to which the personal data was disclosed by us within a year before the date the correction was made.
 
13.2.5 We /may also be charging you a reasonable fee for the handling and processing of your requests to access your personal data. If we so choose to charge, we will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.
 
13.2.6 We reserve the right to refuse to correct your personal data in accordance with the provisions as set out in Privacy Laws, where they require and/or entitle an organization to refuse to correct personal data in stated circumstances.
 
13.3 Requesting to Erase or Destroy or Suspend or Anonymize Personal Data
 
You may request that we erase or destroy or temporarily suspend the use of or anonymize the Personal Data we hold about you in case you believe that the Personal Data we hold about you is being unlawfully processed by us or we are not complying with the Privacy Laws.
 
Please provide as much detail as possible on your reasons for the request to assist us in determining whether you have a valid basis for erasure or destruction or suspension or anonymization, as the case may be. However, we may retain the Personal Data if there are valid grounds under law for us to do so (e.g., for the defence of legal claims or freedom of expression) but we will let you know if that is the case.  Please note that after deleting, destroying, suspending or anonymizing the Personal Data, we may not be able to provide the same level of servicing to you as we will not be aware of your preferences.
 
14. QUESTIONS, CONCERNS OR COMPLAINTS? CONTACT US
 
14.1 If you have any questions or concerns about our privacy practices or your dealings with the Services, please use:
14.2 If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with Privacy Laws, we welcome you to contact us with your complaint or grievance.
 
Please contact us through email with your complaint or grievance:
15. TERMS AND CONDITIONS
 
Please also read the Terms of Service establishing the use, disclaimers, and limitations of liability governing the use of the Platform and the Services and other related policies.
 
Last modified: 15 June 2021