Privacy Policy
Last updated: 2026-09-04 · Applies to Marketplace Bridge operated by PromptPrint.
This Privacy Policy describes how PromptPrint ("we") handles data in the Marketplace Bridge service ("Service"). We take Thailand's Personal Data Protection Act (PDPA) as our baseline for handling personal data.
1. Data we hold
- Marketplace credentials — the API keys, OAuth access and refresh tokens issued by each marketplace for shops you authorise.
- Order data — the full order payload each marketplace delivers to us: buyer name, shipping address, phone, line items, prices, marketplace order id, status transitions.
- Operational logs — timestamps and outcomes of every OAuth exchange, poll, push and retry we perform on your account.
- Admin identity — the sign-in credentials you configure to access the admin console.
2. Purpose & lawful basis
We process this data solely to deliver marketplace orders into your ERP, to keep an audit trail available to you, and to support you. The lawful basis is performance of a contract with you as the account holder and, for marketplace buyer data, legitimate interest in fulfilling the order the buyer placed.
3. Where data lives
All data is stored in a PostgreSQL database operated by us on infrastructure hosted in-country. Marketplace order data is additionally forwarded to your Odoo ERP under your control. We do not use third-party analytics on the admin console.
4. Retention
- OAuth tokens: kept until the shop is disconnected or the token is revoked by the marketplace; refreshed automatically before expiry.
- Order sync records & raw payloads: kept for as long as your account is active; on account termination they are exported on request and deleted within 30 days.
- Operational logs: kept for 12 months rolling.
5. Sharing
We do not sell, share or repurpose your data. The only outbound flow is order payloads forwarded to your own Odoo ERP over an authenticated JSON endpoint. We disclose data only when required by lawful court order after notifying you where legally permitted.
6. Security
- All transport is HTTPS with valid TLS certificates.
- Marketplace webhooks are HMAC-SHA256 signature-verified before processing.
- The admin console is protected by authentication that you configure.
- Marketplace credentials are stored in the Service's own database, isolated from your ERP.
7. Your rights
You may request access to, correction of, or deletion of your account data at any time by contacting us at the address below. For personal data of buyers whose orders flow through the Service, requests should be directed to you as the merchant of record; we will support your response within a reasonable time.
8. Contact
Privacy questions or requests: contact@promptprint.co.th.