PlodScam
Privacy Policy
Effective date: [INSERT DATE] Last updated: [INSERT DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME], trading as PlodScam (“PlodScam”, “we”, “us”, or “our”), handles information when you use this website and its scam-awareness tools. It is intended for use in Thailand and should be reviewed by qualified Thai counsel before publication.
1. Data controller and contact
Data controller: [LEGAL ENTITY NAME]
Registered address: [REGISTERED ADDRESS]
Privacy contact / DPO, if appointed: [PRIVACY CONTACT NAME]
Email: [PRIVACY EMAIL] Telephone: [PRIVACY TELEPHONE]
For Thailand-related privacy questions, requests, or complaints, contact us using the details above. If the issue cannot be resolved, you may contact the Office of the Personal Data Protection Commission (PDPC) through its current official channels.
2. Information we ask you not to submit
Do not submit passwords, one-time passwords (OTPs), bank or payment details, national identification numbers, passport details, health information, intimate images, private conversations unrelated to the check, or any other information that identifies or could seriously affect a person. Remove names, addresses, account numbers, and other personal details before submitting content.
If you submit personal or sensitive information despite this warning, we may process it temporarily to provide the requested assessment and may send it to the third-party AI provider described below. We do not invite or require you to submit such information.
3. What the checker processes
Depending on the tool you use, the service may process the message, URL, phone number, email address, account or page reference, image-derived OCR text, decoded QR or barcode values, extracted URLs, language selection, assessment result, and follow-up conversation context needed to keep an open assessment session working.
For image checks, the uploaded image is processed for OCR, QR/barcode decoding, and assessment. The image itself is not retained in the inquiry database or user history. We retain only the selected text, OCR output, decoded values, and URLs that are required for the assessment record, subject to the retention rules below.
4. Anonymous query records and threat-pattern analysis
We may retain minimized and encrypted query events, assessment results, language, content type, timestamps, and threat categories to operate the service, prevent abuse, investigate reliability, and identify recurring scam patterns. These records are used to build an anonymized threat-intelligence dataset and improve public scam awareness.
The application inquiry record is designed not to contain your name, email address, phone number, account ID, or IP address. Query events are not joined to a user profile. The current application may use a randomly generated technical token, stored only as a one-way protected value, to group related anonymous requests and detect abuse; it is not intended to identify you and is not combined with account or contact information.
Web hosting, security, delivery, and infrastructure providers may separately create technical logs, which can include IP addresses or device information under their own policies. [CONFIRM HOSTINGER LOG RETENTION AND WHETHER A REVERSE-PROXY/CDN IS USED BEFORE FINAL PUBLICATION.] We do not use those infrastructure logs to attach an identity to the inquiry database.
5. Third-party AI assessment provider
To generate an assessment, the content you submit and relevant extracted text may be transmitted to [AI PROVIDER NAME], a third-party AI provider, using its API. This provider may process the submission, prompt, image-derived text, URL context, and follow-up context on our behalf or under its own applicable service terms. Review the provider’s privacy and data-use terms at [AI PROVIDER PRIVACY URL].
We minimize the submission before transmission where technically feasible. We do not promise that a third-party provider will treat a submission as anonymous, retain nothing, or process it only in Thailand. Do not submit anything that you would not accept being processed by this provider.
6. Purposes and legal bases
Subject to the Personal Data Protection Act B.E. 2562 (2019) and applicable subordinate rules, we may process information because it is necessary to provide the requested service, to pursue legitimate interests such as service security and scam-pattern analysis, to comply with a legal obligation, or because you have given consent where consent is required. We will not use personal data for a new incompatible purpose without an appropriate legal basis or notice.
7. Cookies and local storage
We use essential cookies or browser storage to remember language preferences, cookie choices, and limited service state. Optional analytics cookies will not be enabled without the relevant choice. You can block or delete cookies in your browser, but some functions may stop working. A cookie notice does not replace this Privacy Policy.
8. Retention and deletion
We retain minimized query records only for as long as reasonably necessary for the purposes described above, then delete or irreversibly anonymize them. Target retention period: [INSERT PERIOD, FOR EXAMPLE 12 MONTHS]. Assessment-session context is deleted after [INSERT SESSION PERIOD]. Images are deleted after processing and are not retained in inquiry or user-history records, subject to temporary technical caches outside our direct control.
Where a record has been irreversibly anonymized so that it cannot reasonably be linked to you, it may be retained as statistical or threat-pattern information.
9. Security and international transfers
We use HTTPS/TLS in transit, access controls, prepared database statements, encryption for stored inquiry content and results, secret separation, and limited operational access. We aim to apply safeguards that meet or exceed applicable requirements where feasible, but no online service can guarantee absolute security. If a personal-data breach occurs, we will assess and handle it in accordance with applicable Thai law, including any required notification or communication.
Third-party AI, hosting, email, storage, or security providers may process information outside Thailand. Before launch, we will document the relevant provider, transfer mechanism, contractual safeguards, and retention settings in the service register. Transfer details: [INSERT COUNTRIES / PROVIDERS / SAFEGUARDS].
10. Your rights
Subject to legal exceptions and verification requirements, you may request access to, correction of, deletion of, restriction of, or a copy of personal data we hold about you; object to certain processing; withdraw consent where consent is the legal basis; and request information about processing. Because anonymous query records are not linked to an identity, we may be unable to locate or delete a record without information that allows us to distinguish it. We will respond within the period required by applicable law or explain any lawful extension or refusal.
11. Children
The service is not directed to children. Do not submit a child’s personal data. If you believe a child’s information has been submitted, contact us at [PRIVACY EMAIL] so we can assess deletion or other appropriate action.
12. Changes
We may update this notice when the service, providers, law, or processing purposes change. The updated version will show a new effective date. Material changes may be highlighted on the website or communicated through an appropriate channel.
This is a working privacy-notice template, not legal advice. Obtain Thai legal review and complete every bracketed field before relying on it.