TMS Privacy Policy
Effective date: Last updated:
This is a translation of the Thai original. If the two versions conflict, the Thai version governs.
The short version
- We collect what the transport management system needs to work. We do not sell data.
- We use no advertising or analytics cookies. No third-party tracking tools are installed — no Google Analytics, no Meta Pixel, nothing comparable.
- The driver app does not track location continuously. It reads your position only while you are using the app, and only at the moments you record proof, check a vehicle in or out, or change a job status.
- If you are a driver, please read the Driver Privacy Notice, which is written for you specifically.
This summary is for readability. The detail below governs.
1. Who this policy covers
This policy explains how ("we", "us") collects, uses, discloses, and protects personal data, under the Personal Data Protection Act B.E. 2562 ("PDPA").
It covers data relating to:
- Subscribers and organization administrators
- Dispatchers and back-office users
- Drivers and vehicle assistants using the mobile application
- Customer contacts and consignees recorded in the system by customer organizations
- Visitors to our website
1.1 We wear two hats — this determines whom you should contact
We are the Data Controller for account data, authentication data, billing, support, and system security. For these matters, contact us directly at .
We are a Data Processor for the data customer organizations put into the system to run their own transport operations — customer and consignee records, pickup and delivery points, work orders, proof photographs, recipient signatures, and driver operational records.
In that case, the organization that employs or contracts with you is the Data Controller. We process only on that organization's instructions. To exercise your rights over that data, contact that organization first. If you contact us instead, we will forward your request to the relevant organization and tell you where we sent it.
2. What we collect
2.1 Information you give us directly
| Category | Detail |
|---|---|
| Account data | First and last name, email, telephone number, password (stored as a bcrypt hash — never in plain text), profile picture |
| Social login data | Google or LINE user ID, name, email, and profile picture supplied by the provider |
| Organization data | Organization name, address and coordinates, telephone number, corporate documents such as company affidavits or VAT certificates |
| Payment account data | Payment method, bank name, bank account number, account holder name, or PromptPay ID |
| Driving licence data | Licence class, licence number, expiry date, and the uploaded licence document image |
| Vehicle data | Registration plate, type, capacity, and vehicle photographs |
2.2 Data generated through use of the system
| Category | What it contains |
|---|---|
| Work orders and routes | Pickup and delivery names and addresses, coordinates, cargo details, weight, volume, special instructions, requested times |
| Customer contact data | Name, contact name, telephone, email, address, province, district, subdistrict, postcode |
| Dispatch plans | Assigned vehicle, driver, vehicle assistant, driver pay per trip, service fees |
| Operational proof | Pickup photographs, delivery photographs, odometer photographs, and recipient signatures, with capture time and coordinates |
| Vehicle check-in/check-out logs | Odometer reading, photograph, time, and coordinates |
| Job status history | Status changed, who changed it, when, and the coordinates at the moment of change |
| Delivery issue reports | Reason for failed delivery — customer unreachable, wrong address, no recipient, and similar |
| Driver earnings | Monthly totals calculated from dispatch plans |
2.3 Technical and security data
IP address, browser or device type and version, request time, endpoint called, trace ID, and result.
We keep this for security, troubleshooting, and to comply with section 26 of the Computer Crime Act B.E. 2550, which requires service providers to retain computer traffic data for at least 90 days.
2.4 Location data — the actual scope
This section is longer than the others, because location is sensitive and commonly misunderstood.
The driver application requests "while using the app" location permission only. It does not request background location, and it does not track routes continuously.
The system reads coordinates only at these moments:
- When recording proof of pickup or delivery (photograph, signature, odometer photograph)
- When checking a vehicle in or out
- When changing a work order status — starting a job, completing it, or reporting an issue
Outside those moments, the system does not read your position. Once the app is closed, the system does not know where you are.
The "driver position" view a dispatcher sees is not real-time tracking. It shows the last coordinate the app recorded, together with the time it was recorded, so the viewer can judge how stale it is.
If you decline location permission, you can still use the app and complete jobs normally. Proof will be recorded without coordinates — the system is deliberately built this way, because deliveries must proceed even where signal is poor or you choose not to share your position. Your employer may nonetheless have internal rules about this, which is a matter between you and them.
2.5 What we do not collect
We do not store credit card or payment card details in the system.
We do not intentionally collect sensitive personal data under PDPA section 26 — race, religion, political opinion, criminal record, health data, biometric or genetic data.
The system has no fields for such data. However, file upload fields and free-text fields could be misused to enter it. Please do not upload or enter sensitive data into the system. If we find sensitive data has been entered without a legal basis, we will notify the relevant organization to remove it.
We do not track your behaviour across other websites.
3. Where we get data from
- Directly from you — at registration, when completing your profile, uploading documents, or using the system
- From your organization — for example when an administrator invites you or enters your driving licence details on your behalf
- From login providers — Google or LINE supply your name, email, and profile picture when you choose that login method
- From customer organizations — if you are a customer contact or consignee, your data was entered by the organization using the system, not by us
4. What we use data for, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and maintaining accounts, authentication, login, password reset | Account, OTP | Contractual performance (s.24(3)) |
| Core service — managing work orders, dispatch plans, and operations | Work orders, dispatch plans, proof | Contractual performance (s.24(3)) |
| Verifying drivers hold valid licences | Driving licence data | Legal obligation of the employer (s.24(6)) and legitimate interest in safety (s.24(5)) |
| Paying drivers | Payment account data, pay amounts | Contractual performance (s.24(3)) |
| Stamping proof of delivery with coordinates | Coordinates, time | Legitimate interest (s.24(5)) — proving where a delivery occurred, preventing disputes and fraud |
| Notifications about jobs and the system | Account, job data | Contractual performance (s.24(3)) |
| Support and troubleshooting | Account, technical data | Legitimate interest (s.24(5)) |
| Security, fraud prevention, preventing unauthorised access | Technical data, logs | Legitimate interest (s.24(5)) |
| Retaining computer traffic data | Logs | Legal obligation (s.24(6)) — Computer Crime Act s.26 |
| Invoicing, receipts, and accounting records | Account, organization data | Legal obligation (s.24(6)) — Revenue Code |
| Improving and developing the service | Anonymised usage data | Legitimate interest (s.24(5)) |
| Marketing communications | Email address | Consent (s.19) — withdrawable at any time |
4.1 A note on consent
We rely on consent for marketing only. Every other purpose rests on another basis, so declining marketing never prevents you from using the system.
In an employment relationship, the law treats consent as rarely freely given, because of the imbalance of power. For that reason we do not rely on consent as the basis for collecting driver location data. We rely on legitimate interest instead — which carries your right to object under clause 9.
4.2 New purposes
If we intend to use data for a new purpose, we will notify you and obtain fresh consent first, unless the new purpose is clearly compatible with the original one.
5. Who we disclose data to
We do not sell, rent, or trade your personal data. We disclose it only as follows.
5.1 Within your organization
Other users in the same organization see your data according to the permissions your administrator has set. For example, dispatchers see driver names, plans, proof of delivery, and the last recorded coordinate.
The system isolates data between organizations. One organization cannot see another's data.
5.2 Service providers we use (processing on our behalf)
| Provider | Function | Data received | Location |
|---|---|---|---|
| Google LLC | Google account login | Email, name, profile picture | United States |
| Google LLC (Maps Platform) | Map display and address search | Searched addresses and coordinates | United States |
| LINE Corporation | LINE account login | LINE user ID, name, profile picture | Japan / Thailand |
| Amazon Web Services | Verification and password reset emails, system hosting | Email addresses, OTP codes | ap-southeast-1 (Singapore) |
| ThaiBulkSMS | SMS OTP delivery | Telephone number | Thailand |
| Cloudflare, Inc. | File storage and network services | Photographs, documents, signatures | Global / auto |
| Expo, Apple, Google | Mobile app distribution and updates | Device data per their own policies | United States |
These providers are contractually bound to process data only on our instructions and not for their own purposes.
5.3 Legal disclosures
We may disclose data under a court order, subpoena, or order of a competent authority, or where necessary to establish or defend legal claims.
On receiving such a request we verify its validity, disclose only what is necessary, and notify those affected unless the law forbids it.
5.4 Merger or transfer of business
On a merger, acquisition, or transfer of business, data may transfer to the acquirer, who must be bound by this policy. We will give you reasonable prior notice.
6. International transfers
Some providers in clause 5.2 have servers or offices outside Thailand, so personal data is transferred internationally.
We comply with PDPA sections 28 and 29 and the Personal Data Protection Committee Notification on Criteria for Cross-Border Transfer of Personal Data B.E. 2566, relying on:
- Standard Contractual Clauses signed with each provider, and/or
- Necessity for performance of the contract with you
You may request details of the safeguards used at .
7. Cookies and similar technologies
7.1 Cookies our website uses
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
token |
Holds the access token after login | Strictly necessary | Token lifetime |
refresh_token |
Renews your session without re-entering your password | Strictly necessary | 7 days |
| Language cookie | Remembers your chosen language (Thai/English) | Functionally necessary | 1 year |
cookie-consent-accepted |
Remembers that you have seen the cookie notice | Strictly necessary | 1 year |
7.2 What we do not use
We use no advertising, analytics, or cross-site tracking cookies. No Google Analytics, Google Tag Manager, Meta Pixel, Mixpanel, PostHog, Hotjar, or comparable tool is installed.
Because every cookie we use is necessary for the system to function, the law does not require consent before setting them. We disclose them here for transparency.
If you block these cookies in your browser, you will not be able to log in.
7.3 Mobile application
The driver app does not use cookies. It stores the access token in the operating system's encrypted storage (iOS Keychain / Android Keystore), which is more secure than a plain file.
8. How long we keep data
| Data | Retention | Reason |
|---|---|---|
| Active user accounts | For the duration of the service | Necessary to provide the service |
| User accounts after closure | 90 days, then deleted or anonymised | Reactivation window and dispute buffer |
| OTP and verification codes | Deleted on expiry or use, within 30 days at the latest | No reason to retain |
| Work orders and proof of delivery | 5 years from job completion | Limitation period for carriage contracts and dispute evidence |
| Payment account and driving licence data | While you remain a user in the organization, deleted within 90 days after you leave | No reason to retain once you no longer work there |
| Accounting and tax records | 5 years | Revenue Code section 87/3 |
| Computer traffic data (logs) | At least 90 days, no more than 1 year | Computer Crime Act section 26 |
| Whole-organization data after termination | 30-day export window, deleted within 90 days | Per the Data Processing Agreement |
| Anonymised data | Indefinite | No longer personal data |
Where a dispute, legal proceeding, or regulatory investigation is under way, we retain relevant data until it concludes.
9. Your rights
Under the PDPA you have the following rights:
| Right | Section | What it means |
|---|---|---|
| Access and obtain a copy | s.30 | See what data we hold about you and get a copy |
| Data portability | s.31 | Receive data in machine-readable form, or have it sent to another party |
| Object | s.32 | Object to processing, especially where we rely on legitimate interest — such as location data |
| Erasure or anonymisation | s.33 | Ask us to delete data no longer necessary |
| Restriction | s.34 | Ask us to suspend use, for example while accuracy is disputed |
| Rectification | s.35 | Correct inaccurate or outdated data |
| Withdraw consent | s.19 | Withdraw at any time, for anything based on consent (marketing) |
| Complain | s.73 | Complain to the Personal Data Protection Committee Office |
9.1 How to exercise your rights
Send your request to , stating which right you wish to exercise and attaching proof of identity. We ask for proof so that no one else can impersonate you.
We respond within 30 days of receiving a complete request. If a request is complex and needs longer, we will explain why and give a timeframe before the deadline expires.
Exercising your rights is free, unless a request is manifestly excessive or vexatious.
9.2 When we may refuse
We may refuse a request in part where the law allows — for example where we must retain data to meet a legal obligation, to establish or defend legal claims, or where disclosure would affect another person's rights.
We always give reasons for a refusal in writing, and you may appeal or complain further.
9.3 An important limitation
Where the data concerned is controlled by a customer organization (see clause 1.1), we cannot delete or amend it on our own initiative, because we must act on the Controller's instructions. In that case we forward your request to that organization within 7 days and tell you where we sent it.
10. How we protect data
As required by PDPA section 37(1):
Technical measures
- Data encrypted in transit using TLS
- Passwords stored as bcrypt hashes — we do not know your password and cannot recover it
- Access via time-limited tokens, with OTP-based two-step verification at defined points
- Photographs and documents held in non-public storage; access requires a digitally signed link that expires within 15 minutes
- Tenant isolation between organizations at the database level
- Role-based access control
- Rate limiting to prevent credential guessing and bulk extraction
- Access logging with trace identifiers for audit
- In the mobile app, tokens held in the OS encrypted store
Organizational measures
- Access granted only to staff who need it for their duties
- Staff and contractors bound by confidentiality agreements
- Periodic review of access rights and security measures
- Regular backups
That said, no system is perfectly secure and we cannot guarantee absolute security. You can help by using a strong password, not reusing it elsewhere, and never sharing an OTP code with anyone. We never call or message you to ask for your OTP.
11. Data breaches
If a personal data breach occurs, we will:
- Notify the Personal Data Protection Committee Office within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals' rights and freedoms (PDPA s.37(4)).
- Notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, explaining what happened, what data was affected, and what you should do.
- Notify the relevant customer organization without undue delay where the breach affects data they control, so they can meet their own notification obligations in time.
12. Changes to this policy
We may update this policy as the service or the law changes.
For material changes — collecting new categories of data, using data for new purposes, or disclosing to new recipients — we will give at least 30 days' notice by email or in-system notification, and where the law requires fresh consent, we will seek it.
The last-updated date always appears at the top of this document.
13. Contact
Data Controller Email: Telephone:
Data Protection Officer Email:
Supervisory authority Personal Data Protection Committee Office (PDPC) Government Complex, Chaeng Watthana Road, Lak Si, Bangkok 10210, Thailand Website: https://www.pdpc.or.th
This document exists in Thai and English. If they conflict, the Thai version governs.