Privacy policy
This English version is provided for convenience. If it differs from the Thai version, the Thai version prevails.
The website and the program collect only the personal data needed to provide the service, in line with Thailand's Personal Data Protection Act B.E. 2562 (2019).
What is collected
- Account: username, email, and your password turned into a hash (Argon2). Nobody can see your actual password, administrators included.
- Connected computers: a random installation ID the program creates, the computer's name, the versions of the program and of Windows, and when it last checked its right, so you can tell your computers apart. No hardware serial numbers.
- Signing in with Google or Facebook (if you use it): the account ID the provider gives, the email address the provider has verified, and your display name, used only to sign you in. The service never receives your password there or access to anything else in that account.
- Profile picture (if you set one): the picture you choose, scaled to 192×192 pixels in your browser before it is sent and saved again without any hidden data in the file. Shown only on your account page and in the program on computers connected to your account; you can remove it at any time.
- Orders: the plan, the amount, the date and time, and the transfer reference you report.
- Reports from the program: what you type, the reply address if you give one, the versions of the program and of Windows, and the account connected on that computer, if any.
- Technical data: your IP address is turned into a temporary hash to limit unusually frequent use and to count downloads, and deleted within about a day.
What is not collected
- Your macro files, and anything you type or record in the program, stay on your computer only and are never sent to the server.
- Checking for updates sends no personal data.
- The website uses no advertising cookies or third-party trackers, only the sign-in cookie it needs to work.
What the data is used for
- Confirming who you are, and sending the emails that verify an account and reset a password.
- Checking payments and opening paid rights.
- Preventing fraud and keeping the system secure.
- Answering what you report or ask about.
Sharing
Your data is never sold or passed on for marketing. It goes only to the service providers that are strictly needed: the email provider, the website's network and security provider, and the payment provider where one is used.
How long it is kept
- Account data is kept for as long as the account exists.
- A website sign-in expires after 1 day. A connected computer's right expires after 90 days unless it is renewed.
- Order records are kept as long as accounting and tax rules require.
- Backups are encrypted, and old ones are deleted on a schedule.
Your rights
You can download a copy of your data, and delete your account yourself, on your account page. You can also ask to access, correct or delete your data through the contact page. Deleting the account ends its paid rights and disconnects all its computers; order records may have to be kept for as long as the law requires.
Security
The website uses an encrypted connection (HTTPS), passwords are stored as hashes, and the administrator console requires two-step verification.