Effective date: 9/2/2026 | Last updated: 9/8/2026
Effective: 2 September 2026 Last updated: 8 September 2026
This notice is given under Section 23 of the Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). It tells you what personal data we collect, why we collect it, the lawful basis we rely on, how long we keep it, who we share it with, and what rights you have.
| Item | Detail |
|---|---|
| Legal entity | BUMMIRAS LIVING COMPANY LIMITED (บริษัท บูมมิรัส ลิฟวิ่ง จำกัด) |
| Company registration / Tax ID | 0105552020803 |
| VAT status | VAT registered |
| Registered office | 888/97-100 Moo 3, Bang Pu Mai Sub-district, Mueang Samut Prakan District, Samut Prakan 10280, Thailand |
| Trading brand | BUMMIRAS |
How to reach us about your data
We are not required to appoint a Data Protection Officer under Section 41 of the PDPA, because our core activity is not large-scale data processing as defined there. A named person inside the company handles these matters and receives requests through the channels above.
| Category | Detail |
|---|---|
| Identity and contact | Full name, display name, email address, telephone number |
| Gender | Only if you choose to enter it — optional |
| Profile picture | Only if you upload one. Stored in non-public storage, reachable only through a time-limited link |
| Addresses | Delivery address and tax invoice address |
| Taxpayer details | Taxpayer name, taxpayer identification number, taxpayer type — only when you request a tax invoice |
| Messages you send us | Text you submit through contact forms or rights requests |
| Category | Detail |
|---|---|
| Account data | One-way hashed password, authentication method, sign-in history |
| Order data | Order number, items, made-to-order selections, prices, status and status history |
| Payment data | Payment status, amount, the payment provider's transaction reference, card brand, last four digits, and card expiry month and year. We never store the full card number, CVV, cardholder name, or the cross-merchant card fingerprint on our systems. |
| Cart and wishlist | Items you have selected but not yet ordered |
| Referral code | The referral code you enter at checkout, if any, and the link between your order and the referring salesperson, used to calculate your discount and the referrer's commission |
| Notification data | The browser push endpoint, only if you grant permission |
| Cookies and device data | See the Cookie Policy for the full list |
| System records | Technical records kept for security and audit. We do not write names or phone numbers into audit records — only which field was changed. |
If you sign in with Google, Facebook or LINE, we receive your name, email address and profile picture from that provider, limited to what you permit. We never receive your password for those accounts.
We do not collect sensitive personal data as defined in Section 26 of the PDPA (such as race, religion, health data or biometric data). If you send such data to us through a free-text field, we delete it when we find it.
This service is not intended for people under 20 to contract on their own. If you are under 20, a purchase requires the consent of the person with parental authority under Section 20 of the PDPA. If we learn that we hold a minor's data without valid consent, we delete it.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and maintain your account, verify your identity | Identity data, account data | Contract — Section 24(3) |
| Take orders, take payment, deliver, provide after-sales service | Order data, addresses, payment data | Contract — Section 24(3) |
| Issue tax invoices and keep accounting records | Taxpayer details, order data | Legal obligation — Section 24(6), Revenue Code |
| Prevent fraud and keep the service secure | System records, device data | Legitimate interest — Section 24(5) |
| Tell you about your order status | Email, telephone number | Contract — Section 24(3) |
| Run the referral-code programme (your discount and the referring salesperson's commission) | Referral code, order data | Contract — Section 24(3) |
| Send browser push notifications | Push endpoint | Consent — Section 19, withdrawable at any time |
| Cookies and similar technologies | See Cookie Policy | Strictly necessary cookies: legitimate interest. All others: consent — Section 19 |
We do not use automated decision-making or profiling that produces legal effects for you within the meaning of Section 32(1).
We currently email you only about your orders and your account — identity verification, order confirmation and delivery updates. We do not send marketing email. If we start, we will ask for your consent separately first and include an unsubscribe link in every message.
If we ever want to use your data for a purpose not listed above, we will tell you and obtain fresh consent first.
We share only what is necessary, and we bind each recipient to use the data only on our instructions.
| Recipient | Role | What they receive |
|---|---|---|
| Omise (Opn Payments) | Payment processor, PCI-DSS certified | Card details you enter directly on their form, the amount, and the order reference |
| Supabase Inc. | Database and authentication provider | All data stored in the service |
| Google LLC (Gmail) and Resend, Inc. | Email delivery providers — we currently send email through the company Gmail account and will move to Resend once our domain is verified | Your email address, name, and the content of emails we send you |
| Google LLC / Meta Platforms, Inc. / LINE Corporation | Sign-in providers | Only if you choose to sign in through them |
| Our own delivery team and partner carriers | Delivery | Name, delivery address, telephone number, items |
| Government agencies, courts, and authorised officers | Legal process | Only as required by a lawful order |
We do not sell, rent or trade your personal data for marketing purposes.
Using this service involves storing or processing data outside Thailand, under Sections 28 and 29 of the PDPA.
| Recipient | Country of processing |
|---|---|
| Supabase Inc. | Singapore (database region for this service) and the United States (parent company) |
| Google LLC (Gmail) / Resend, Inc. | United States |
| Google LLC / Meta Platforms, Inc. | United States |
| LINE Corporation | Japan |
| Omise (Opn Payments) | Thailand and Singapore |
Some destination countries may not have data protection standards equivalent to Thailand's. We therefore protect these transfers through data protection terms agreed with each provider, in line with the criteria issued by the Personal Data Protection Committee for transfers abroad. You may ask to see details of these safeguards using the contacts in Section 1.
| Category | Retention | Reason |
|---|---|---|
| Accounting records and tax invoices | 5 years from the date of the document | Section 87/3 of the Revenue Code — this data cannot be deleted early even if you exercise your right to erasure |
| Order and payment data | 5 years from completion | Legal obligation and dispute resolution |
| Account data | While the account is active; deleted or anonymised when you close it | Contract |
| Audit records | 2 years, then deleted automatically | Security |
| Technical event records | Most recent 50,000 records; the system deletes the oldest automatically | Security |
| Cart and wishlist | Until you clear them, or when you close your account | Contract |
| Marketing data | Until you withdraw consent | Consent |
After these periods we delete the data or render it non-identifiable.
You may exercise these rights free of charge.
| Right | What it means | Section |
|---|---|---|
| 1. Access and obtain a copy | See the data we hold about you and how we obtained it | 30 |
| 2. Data portability | Receive your data in a machine-readable form, or have it sent to another controller | 31 |
| 3. Object | Object to processing based on legitimate interest, and to direct marketing | 32 |
| 4. Erasure | Ask us to delete your data or make it non-identifiable | 33 |
| 5. Restriction | Ask us to stop using your data temporarily without deleting it | 34 |
| 6. Rectification | Ask us to correct data that is wrong, out of date or incomplete | 35 |
| 7. Withdraw consent | Withdraw consent at any time, without affecting processing already carried out lawfully | 19, fifth paragraph |
| 8. Complain | Complain to the Personal Data Protection Committee if you believe we are not complying | 73 |
How to exercise them
1. Things you can do yourself, right now — sign in and go to My Account - Correct your data (right 6): change your display name, gender and telephone number on the account page; change addresses on the addresses page - Delete your account (right 4): the "Delete account" button at the bottom of the account page - Withdraw push notification consent (right 7): turn off notification permission for this site in your browser settings - Withdraw cookie consent (right 7): the "Cookie settings" button at the end of the Cookie Policy page 2. Things that need a request — for access and copies (right 1), portability (right 2), objection (right 3) and restriction (right 5), email bummiras@gmail.com with your name, the email address on your account, and which right you wish to exercise. We will provide the data in a machine-readable file.
We may ask you to verify your identity to prevent someone else exercising your rights. We will complete your request within 30 days of receiving it, as required by Section 30. If we refuse, we will record our reasons and tell you.
One limitation you should know about: if you have an order in production or in transit, we cannot delete your delivery address until delivery is complete, because neither you nor we would be able to track the shipment. Data held in accounting documents must also be kept for the periods in Section 6.
Complaining to the regulator Office of the Personal Data Protection Committee (PDPC), 7th Floor, Ratthaprasasanabhakti Building, Government Complex, Chaeng Watthana Road, Thung Song Hong, Lak Si, Bangkok 10210, Thailand — https://www.pdpc.or.th
This service is aimed at customers in Thailand and we deliver only within Thailand. If you browse the site from the EEA or the UK, the GDPR or UK GDPR may apply to that processing. Where it does:
We have not appointed an EU or UK representative under Article 27 GDPR, because we do not offer goods or services to, or monitor the behaviour of, people in those territories.
We apply technical and organisational measures under Section 37(1) of the PDPA:
If a personal data breach occurs, we will notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it, and notify you without delay where the breach is likely to result in a high risk to your rights and freedoms, as required by Section 37(4).
The full list of cookies this service uses, their purpose, lifetime and how to manage them is in the Cookie Policy.
We will update this notice whenever our processing changes or the law changes, and we will always show the effective date at the top. If a change materially affects your rights, we will tell you in advance by email or by a notice on the site.
This notice is governed by Thai law, in particular the Personal Data Protection Act B.E. 2562 (2019), and is to be read together with the Terms of Service.
Email: bummiras@gmail.com | Phone: +66851202053