นโยบายความเป็นส่วนตัว
นโยบายความเป็นส่วนตัว (“นโยบาย”) ฉบับนี้อธิบายวิธีที่ BuddyCal (“เรา”) เก็บรวบรวม ใช้ เปิดเผย โอน และคุ้มครองข้อมูลส่วนบุคคลของคุณ เมื่อคุณใช้แอปพลิเคชัน BuddyCal และเว็บไซต์ที่เกี่ยวข้อง (“บริการ”) นโยบายนี้จัดทำให้สอดคล้องกับพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA) และกฎหมายที่เกี่ยวข้อง
1. ข้อมูลที่เราเก็บรวบรวม
เราอาจเก็บข้อมูลประเภทต่อไปนี้ ขึ้นกับฟีเจอร์ที่คุณใช้งาน:
- ข้อมูลบัญชีและการติดต่อ — อีเมล รหัสผู้ใช้ (user ID) ข้อมูลการยืนยันตัวตน และข้อมูลที่ได้จากการเข้าสู่ระบบผ่านบุคคลที่สาม (เช่น Apple Sign In)
- ข้อมูลโปรไฟล์และเป้าหมายสุขภาพ — อายุ/ช่วงอายุ เพศ (หากระบุ) ส่วนสูง น้ำหนัก เป้าหมายน้ำหนัก เป้าหมายแคลอรีรายวัน และข้อมูลโภชนาการที่คุณกรอก
- รูปภาพ — รูปภาพอาหารที่คุณถ่ายหรืออัปโหลดเพื่อประเมินแคลอรี่ รูปโปรไฟล์ (หากเลือกเพิ่ม) และข้อมูลเมตาของรูปภาพ (เช่น วันที่ถ่าย)
- ข้อมูลกิจกรรมและการเคลื่อนไหว — จำนวนก้าว ระยะทาง (หากรองรับ) เป้าหมายก้าวรายวัน และข้อมูลกิจกรรมจากเซ็นเซอร์อุปกรณ์หรือ Apple Health (หากคุณอนุญาต)
- บันทึกการใช้งาน — ประวัติมื้ออาหาร แคลอรี่ที่บันทึก ไทม์ไลน์รายวัน และการตั้งค่าในแอป
- ข้อมูลการใช้งานและอุปกรณ์ — เหตุการณ์การใช้งานในแอป (หน้าจอที่เปิด ปุ่มที่กด) รุ่นอุปกรณ์ เวอร์ชันระบบปฏิบัติการ ภาษา เวอร์ชันแอป และที่อยู่ IP (เพื่อความปลอดภัย)
เราไม่เปิดให้ผู้ใช้โพสต์เนื้อหาสาธารณะภายในแอป ข้อมูลที่คุณกรอกหรืออัปโหลดเพื่อใช้งานฟีเจอร์ยังถือเป็นข้อมูลส่วนบุคคลของคุณ
2. แหล่งที่มาของข้อมูล
- จากคุณโดยตรง — เมื่อสมัครบัญชี กรอกโปรไฟล์ ถ่ายรูปอาหาร หรือใช้งานฟีเจอร์ต่าง ๆ
- จากอุปกรณ์ของคุณ — เซ็นเซอร์นับก้าว Apple HealthKit (หากอนุญาต) และข้อมูลอุปกรณ์
- อัตโนมัติ — ผ่านระบบ analytics บันทึกระบบ และโครงสร้างพื้นฐานเพื่อการทำงานของแอป
3. วัตถุประสงค์และฐานทางกฎหมายในการประมวลผล
เราใช้ข้อมูลเพื่อ:
- ให้บริการหลัก — สร้างบัญชี ประเมินแคลอรี่จากรูปภาพ นับก้าว บันทึกและแสดงผลข้อมูลสุขภาพ
- ปรับปรุงบริการ — วิเคราะห์การใช้งาน แก้ไขข้อบกพร่อง พัฒนาความแม่นยำของระบบประเมินแคลอรี่
- ความปลอดภัย — ป้องกันการใช้งานผิดปกติ การโจมตี และการฉ้อโกง
- การสื่อสาร — ตอบคำถาม ให้การสนับสนุนผู้ใช้ และแจ้งการเปลี่ยนแปลงสำคัญของบริการ
- ปฏิบัติตามกฎหมาย — ตามที่กฎหมายกำหนด
ฐานทางกฎหมายอาจรวมถึง: การจำเป็นเพื่อให้บริการตามคำขอของคุณ (สัญญา) ประโยชน์โดยชอบด้วยกฎหมายของเรา (ความปลอดภัย/การปรับปรุงบริการ) และ/หรือความยินยอม (ในกรณีที่กฎหมายกำหนด เช่น ข้อมูลอ่อนไหวหรือการเชื่อมต่อ HealthKit)
4. ข้อมูลอ่อนไหว (ข้อมูลสุขภาพ)
ข้อมูลสุขภาพและโภชนาการบางอย่าง (เช่น น้ำหนัก เป้าหมายแคลอรี ข้อมูลจาก HealthKit) อาจถูกจัดเป็นข้อมูลอ่อนไหวตาม PDPA
เราใช้ข้อมูลดังกล่าวเพื่อให้บริการฟีเจอร์ด้านสุขภาพ/โภชนาการเท่านั้น ใช้มาตรการรักษาความปลอดภัยที่เหมาะสม และจะขอความยินยอมเพิ่มเติมผ่านหน้าจอในแอปเมื่อกฎหมายกำหนด
5. การเปิดเผยข้อมูลและผู้ประมวลผลข้อมูล
เราอาจเปิดเผยหรือให้ผู้ให้บริการประมวลผลข้อมูลแทนเรา เพื่อวัตถุประสงค์ในนโยบายนี้:
- Supabase — ฐานข้อมูล การยืนยันตัวตน และโครงสร้างพื้นฐาน backend
- Apple — App Store การชำระเงิน (หากมีการสมัครสมาชิก) และ Apple Sign In
- ผู้ให้บริการ AI/ML — ประมวลผลรูปภาพอาหารเพื่อประเมินแคลอรี่ (ข้อมูลถูกส่งเฉพาะเท่าที่จำเป็น)
- ผู้ให้บริการ Analytics — วิเคราะห์การใช้งานแอปเพื่อปรับปรุงประสบการณ์ผู้ใช้
เราไม่ขาย ให้เช่า หรือแลกเปลี่ยนข้อมูลส่วนบุคคลของคุณกับบุคคลที่สามเพื่อวัตถุประสงค์ทางการตลาด
เราอาจเปิดเผยข้อมูลเมื่อกฎหมายกำหนด หรือเพื่อปกป้องสิทธิ ความปลอดภัย และทรัพย์สินของเราและผู้ใช้
6. การโอนข้อมูลไปต่างประเทศ
ข้อมูลอาจถูกจัดเก็บหรือประมวลผลบนเซิร์ฟเวอร์ที่อยู่นอกประเทศไทย ขึ้นกับผู้ให้บริการ (เช่น Supabase, Apple, ผู้ให้บริการ AI)
เราจะใช้มาตรการที่เหมาะสม เช่น ข้อตกลงมาตรฐานการคุ้มครองข้อมูล หรือมาตรการตามที่ PDPA กำหนด เพื่อให้การโอนข้อมูลเป็นไปตามกฎหมาย
7. ระยะเวลาในการเก็บรักษาข้อมูล
- ข้อมูลบัญชี/โปรไฟล์ — เก็บไว้ตราบเท่าที่คุณมีบัญชี หรือจนกว่าคุณจะขอลบ
- รูปภาพอาหารและบันทึกมื้ออาหาร — เก็บไว้ตามระยะเวลาที่จำเป็นเพื่อให้บริการ หรือจนกว่าคุณจะลบ
- ข้อมูล analytics และบันทึกระบบ — เก็บตามรอบเวลามาตรฐานของผู้ให้บริการ หรือเท่าที่จำเป็นเพื่อความปลอดภัยและการปรับปรุงบริการ (โดยทั่วไปไม่เกิน 24 เดือน)
เมื่อหมดความจำเป็น เราจะลบหรือทำให้ข้อมูลไม่สามารถระบุตัวบุคคลได้
8. สิทธิของเจ้าของข้อมูล
ภายใต้ PDPA และกฎหมายที่ใช้บังคับ คุณมีสิทธิ:
- ขอเข้าถึงและรับสำเนาข้อมูลส่วนบุคคลของคุณ
- ขอให้แก้ไขข้อมูลให้ถูกต้อง ครบถ้วน และเป็นปัจจุบัน
- ขอให้ลบหรือทำลายข้อมูล เมื่อหมดความจำเป็น
- ขอให้ระงับการใช้ข้อมูลในบางกรณี
- คัดค้านการประมวลผลในบางกรณี
- ขอให้โอนข้อมูล (data portability) ตามที่กฎหมายกำหนด
- ถอนความยินยอม (หากเราอาศัยความยินยอม) โดยไม่กระทบการประมวลผลก่อนหน้า
คุณสามารถใช้สิทธิได้โดยติดต่อ support@calbuddy.live เราจะดำเนินการภายในระยะเวลาที่กฎหมายกำหนด (โดยทั่วไปไม่เกิน 30 วัน)
9. ความปลอดภัยของข้อมูล
เราใช้มาตรการรักษาความปลอดภัยที่เหมาะสม ได้แก่:
- การเข้ารหัสข้อมูลระหว่างส่ง (TLS/HTTPS)
- การควบคุมการเข้าถึงและการแยกสิทธิภายในระบบ
- แนวทางความปลอดภัยของผู้ให้บริการโครงสร้างพื้นฐาน (เช่น Supabase)
- การตรวจสอบและอัปเดตระบบเป็นประจำ
อย่างไรก็ตาม ไม่มีระบบใดปลอดภัย 100% เราไม่สามารถรับประกันความปลอดภัยอย่างสมบูรณ์ได้
10. คุกกี้และเทคโนโลยีติดตาม
เว็บไซต์ของเราอาจใช้คุกกี้และเทคโนโลยีที่คล้ายกันเพื่อการทำงานพื้นฐาน การจดจำการตั้งค่า และการวิเคราะห์การใช้งาน รายละเอียดเพิ่มเติมอยู่ใน นโยบายคุกกี้
แอปมือถืออาจใช้ตัวระบุอุปกรณ์และเครื่องมือ analytics ภายในแอปตามที่ระบุในส่วนที่ 1 และ 5 ของนโยบายนี้
11. ความเป็นส่วนตัวของเด็ก
บริการกำหนดอายุขั้นต่ำ 13 ปี เราไม่ได้ตั้งใจเก็บข้อมูลจากเด็กอายุต่ำกว่า 13 ปี
หากคุณเชื่อว่าเด็กอายุต่ำกว่า 13 ปีได้ให้ข้อมูลกับเรา กรุณาติดต่อ support@calbuddy.live เพื่อให้เราดำเนินการลบข้อมูล
12. การเปลี่ยนแปลงนโยบายนี้
เราอาจปรับปรุงนโยบายนี้เป็นครั้งคราว โดยจะแจ้งให้ทราบผ่านแอป เว็บไซต์ หรือช่องทางที่เหมาะสม และจะอัปเดตวันที่มีผลบังคับใช้ด้านบน
การใช้งานต่อหลังวันที่มีผลบังคับใช้ของฉบับแก้ไข ถือว่าคุณรับทราบนโยบายที่แก้ไขแล้ว หากมีการเปลี่ยนแปลงที่มีผลกระทบสำคัญ เราจะแจ้งให้ทราบอย่างชัดเจน
สำหรับข้อกำหนดการใช้งาน โปรดดู ข้อกำหนดและเงื่อนไขการใช้งาน
This Privacy Policy (“Policy”) explains how BuddyCal (“we”, “us”, “our”) collects, uses, discloses, transfers, and protects your personal data when you use the BuddyCal mobile application and related website (“Services”). This Policy is designed to comply with Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) and applicable laws.
1. Data We Collect
Depending on the features you use, we may collect:
- Account & contact data — Email, user ID, authentication data, and information from third-party sign-in (e.g., Apple Sign In)
- Profile & health goals — Age/age range, gender (if provided), height, weight, weight goals, daily calorie targets, and nutrition information you enter
- Photos — Meal photos you take or upload for calorie estimation, profile photos (if added), and image metadata (e.g., capture date)
- Activity & movement data — Step count, distance (if supported), daily step goals, and activity data from device sensors or Apple Health (if you authorize)
- Usage logs — Meal history, logged calories, daily timeline, and in-app settings
- Usage & device data — In-app events (screens viewed, buttons tapped), device model, OS version, language, app version, and IP address (for security)
We do not provide a public user-generated content posting feature. Data you enter or upload to use features remains your personal data.
2. Sources of Data
- From you directly — When you sign up, complete your profile, take meal photos, or use features
- From your device — Step sensors, Apple HealthKit (if authorized), and device information
- Automatically — Through analytics, system logs, and infrastructure to operate the app
3. How We Use Data (Purposes & Legal Bases)
We use your data to:
- Provide core services — Account creation, calorie estimation from photos, step tracking, and health data display
- Improve the Services — Usage analytics, bug fixes, and calorie estimation accuracy improvements
- Security — Prevent abuse, attacks, and fraud
- Communication — Support, user assistance, and important service notices
- Legal compliance — As required by law
Legal bases may include necessity to provide the Services you request (contract), our legitimate interests (security/improvement), and/or consent where required (e.g., sensitive data or HealthKit connections).
4. Sensitive Data (Health Information)
Some health and nutrition data (e.g., weight, calorie targets, HealthKit data) may be considered sensitive under the PDPA.
We use such data only to provide health/nutrition features, apply appropriate safeguards, and request additional consent through in-app flows where required by law.
5. Sharing & Processors
We may share data with service providers acting as processors, including:
- Supabase — Database, authentication, and backend infrastructure
- Apple — App Store, payments (if subscriptions are offered), and Apple Sign In
- AI/ML providers — Processing meal photos for calorie estimation (only data necessary for the task)
- Analytics providers — App usage analysis to improve user experience
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
We may disclose data when required by law or to protect the rights, safety, and property of us and our users.
6. International Data Transfers
Your data may be stored or processed outside Thailand depending on our providers (e.g., Supabase, Apple, AI providers).
We apply appropriate measures, such as standard contractual clauses or measures required by the PDPA, to ensure lawful transfers.
7. Data Retention
- Account/profile data — Retained while your account is active or until you request deletion
- Meal photos and food logs — Retained as needed to provide the Service or until you delete them
- Analytics and system logs — Retained per provider defaults or as needed for security and improvement (typically up to 24 months)
When no longer necessary, we delete or anonymize the data.
8. Your Rights
Under the PDPA and applicable law, you may have the right to:
- Access and obtain a copy of your personal data
- Request correction of inaccurate or incomplete data
- Request deletion or destruction when no longer necessary
- Request restriction of processing in certain cases
- Object to processing in certain cases
- Request data portability where applicable
- Withdraw consent (where we rely on consent) without affecting prior processing
Exercise your rights by contacting support@calbuddy.live. We will respond within the timeframe required by law (typically within 30 days).
9. Security
We implement appropriate safeguards, including:
- Encryption in transit (TLS/HTTPS)
- Access controls and role-based permissions
- Security practices of infrastructure providers (e.g., Supabase)
- Regular system monitoring and updates
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. Cookies & Tracking Technologies
Our website may use cookies and similar technologies for essential functionality, preference storage, and usage analytics. See our Cookie Policy for details.
The mobile app may use device identifiers and in-app analytics as described in sections 1 and 5 of this Policy.
11. Children’s Privacy
The Services are intended for users aged 13 and above. We do not knowingly collect data from children under 13.
If you believe a child under 13 provided data to us, contact support@calbuddy.live to request deletion.
12. Updates to This Policy
We may update this Policy from time to time. We will notify you via the app, website, or other appropriate means and update the effective date above.
Continued use after the effective date constitutes acknowledgment of the updated Policy. For material changes, we will provide clear notice.
For terms of use, see our Terms of Service.