
Last updated: 18 April 2026
This Privacy Policy explains how ezZzy Marketplace collects, uses, discloses, and protects your personal data in compliance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA). We are committed to protecting your privacy and your rights as a data subject.
ezZzy Co., Ltd. is the data controller responsible for your personal data.
Contact: privacy@ezzzy.shop
Data Protection Officer: dpo@ezzzy.shop
Information you provide: Name, email address, phone number, shipping address, payment information, identity documents (for seller verification), profile photos.
Transaction data: Purchase history, order details, payment records, auction bids, reviews and ratings.
Device information: IP address, browser type, device identifiers, operating system.
Usage data: Pages visited, search queries, interactions with listings, time spent on pages.
Communication data: Messages between buyers and sellers, support tickets, notification preferences.
Contractual necessity: Processing orders, managing your account, facilitating transactions between buyers and sellers, providing customer support.
Legal obligation: Tax compliance, fraud prevention, responding to lawful government requests, anti-money laundering (AMLO) reporting for transactions over 2,000,000 THB.
Consent: Marketing communications, analytics cookies, personalized recommendations, newsletters. You may withdraw consent at any time.
Legitimate interests: Platform security, fraud detection, service improvement, statistical analysis — balanced against your fundamental rights.
We share your data with:
• Sellers/Buyers: Name, shipping address, and order details necessary to complete transactions.
• Payment processors: Payment information to process transactions securely.
• Shipping providers: Delivery address and contact details for order fulfillment.
• Identity verification services: Documents submitted for seller/KYC verification.
• Law enforcement: When required by Thai law or court order.
• Service providers: Email delivery, analytics, cloud hosting — bound by data processing agreements.
We never sell your personal data to third parties.
Under the PDPA, you have the following rights:
• Right of access (Section 30): Request a copy of your personal data. We will respond within 30 days.
• Right to data portability (Section 31): Receive your data in a structured, machine-readable format.
• Right to object (Section 32): Object to processing based on legitimate interests, including direct marketing.
• Right to erasure (Section 33): Request deletion when data is no longer necessary, you withdraw consent, or processing was unlawful.
• Right to restriction (Section 34): Request that we limit processing in certain circumstances.
• Right to rectification (Section 35): Correct inaccurate or incomplete personal data.
• Right to withdraw consent (Section 19(5)): Withdraw consent at any time, without affecting the lawfulness of prior processing.
• Right to lodge a complaint (Section 73): File a complaint with the Personal Data Protection Committee (PDPC).
To exercise any right, contact: privacy@ezzzy.shop. We will respond within 30 days.
We retain your data as follows:
• Account data: As long as your account is active, plus 30 days after deletion request.
• Transaction records: 5 years after the transaction (as required by the Revenue Code for tax purposes).
• Identity verification documents: Duration of account plus 5 years (AML requirements).
• Communication logs: 2 years from date of communication.
• Analytics data: Anonymized after 24 months.
When retention periods expire, data is securely deleted or anonymized.
Your data may be processed on servers located outside Thailand for cloud hosting and service delivery.
We only transfer data to countries with adequate data protection standards as determined by the PDPC, or under:
• Your explicit consent.
• Contractual necessity (e.g., international shipping).
• Standard contractual clauses or binding corporate rules.
We ensure appropriate safeguards are in place for all cross-border transfers.
We implement technical and organizational measures including: encryption in transit (TLS) and at rest, access controls, secure authentication, regular security audits, and incident response procedures.
In the event of a data breach that may affect your rights, we will notify the PDPC within 72 hours and inform you without delay if the breach poses a high risk to you (PDPA Section 37(4)).
We use cookies and similar technologies. Essential cookies (authentication, cart, security) do not require consent. Analytics, preference, and marketing cookies require your explicit opt-in consent.
See our Cookie Policy for full details and granular controls.
ezZzy is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If we learn that we have collected data from a child under 18, we will delete it promptly.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be notified via email or platform notification.
The "Last Updated" date at the top indicates the most recent revision.
If you believe your data protection rights have been violated, you may:
• Contact us at privacy@ezzzy.shop.
• Lodge a complaint with the Personal Data Protection Committee (PDPC) at www.pdpc.or.th.
Penalties for PDPA violations include: administrative fines up to 5,000,000 THB, criminal fines up to 1,000,000 THB and/or imprisonment up to 1 year, and civil liability including punitive damages up to 2x actual damages.
Legal Disclaimer: This document is provided for informational purposes. For definitive legal advice, consult a Thai-licensed attorney. The Thai-language version of this document prevails in case of any conflict.
Questions? Contact us at support@ezzzy.shop