Privacy Policy
"Pai Duay Kan" (ไปด้วยกัน) Application
Last updated: 3 August 2026 Effective date: 3 August 2026 · Version: 1.0
Summary
Topic · Key points
What we collect — Account information, elderly person's information (including health data), location, proof of payment, booking history, chat messages, and device information
What we use it for — Identity verification, caregiver matching, processing bookings and verifying payments, notifications, and security
Who we share it with — The caregiver you book and the technology providers we rely on (see Section 7) — we do not sell your data and we do not use health data for advertising
Cross-app tracking? — No. We do not track your behaviour across other companies' apps or websites
How to delete your data — Delete your account yourself in the app at Profile → Settings → Delete account. We will delete it within 30 days (see Section 12)
Contact — nat.sri@mulberrysoft.com (see Section 18)
Mulberrysoft Co., Ltd. ("the Company", "we") is committed to protecting the personal data of users of the "Pai Duay Kan" application — a platform that connects elderly individuals and their families with caregivers to book care services, manage the elderly person's health and personal information, and communicate with caregivers through in-app chat and notifications.
This policy explains how we collect, use, disclose, and protect your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). If you do not agree with this policy, please discontinue use of the application.
1. Information We Collect
We collect the following information when you use the application.
Account information: full name, phone number, email address, date of birth, profile photo, and OTP verification data.
National ID number: we request the primary user's national ID number in order to verify identity before granting access to an elderly person's health data, to prevent impersonation, and to prevent fake accounts on a platform that provides in-home services. We store only the ID number; we do not store a photograph of the user's ID card.
Elderly person's information (where you register on behalf of another person): full name, date of birth, service address, level of self-reliance, and relationship to the family member managing the account, as well as health data and blood group, which constitute sensitive personal data under Section 26 of the PDPA (see the consent conditions in Section 4).
Location data (geolocation): latitude/longitude coordinates, used to match you with nearby caregivers. The app reads your location on demand during use. There is no continuous or background location tracking.
Payment information: proof of transfer (payment slip) for payments you make directly via each caregiver's or partner's own PromptPay QR code. We do not store your bank account or card details, and we neither receive nor hold your funds.
Usage information: booking history, chat messages with caregivers, and service ratings and reviews.
Device information: device model, operating system, device identifier, IP address, and the device token used to deliver notifications.
2. Information Recorded by Caregivers During Service
To evidence that the service actually took place as booked, and to protect both you and the caregiver, the system requires caregivers to record the following information while working. This information relates to you and to the service location.
Check-in photographs taken at the service location
The caregiver's location coordinates at the moment each work step is confirmed, which will correspond to your service location
Work step records, including the step name, confirmation time, notes, and whether a step was skipped
Requirements imposed on caregivers: caregivers are permitted to take photographs solely to evidence performance of the work, and are prohibited from photographing the face of the elderly person or anyone in the household without consent, and from taking any image or information outside the application.
Access and deletion: you can view this information on your booking detail page and may request deletion of any image you consider inappropriate through the channels in Section 18. We retain photographs and work records for the periods stated in Section 12 for dispute resolution purposes.
3. Legal Bases for Processing
We process your data on the following legal bases.
Contractual necessity — to create your account, process bookings, and provide the services you request
Consent — for sensitive data (health data, blood group) and for location access. You may withdraw consent at any time
Legitimate interests — to prevent fraud, maintain system security, evidence service delivery, resolve disputes, and improve service quality
Legal obligation — to comply with tax and accounting law, the Computer Crime Act, and orders from competent authorities
4. Consent for Sensitive Data and Registration on Behalf of an Elderly Person
Sensitive data: an elderly person's health data and blood group are sensitive personal data. We will process and disclose such data to the caregiver you book only where separate explicit consent has been obtained from you or from the data subject, and will use it only to the extent necessary to deliver care safely.
Consent for sensitive data is a separate item from acceptance of the Terms of Service. You may use certain booking services without granting this consent, but caregivers will not be able to see the elderly person's health data.
Registering on behalf of an elderly person: where you register or provide information on behalf of an elderly person, you represent that you have obtained that person's consent, or that you hold legal authority to act (for example as a guardian or curator). We may ask you to produce evidence of such consent or authority. The elderly person remains the data subject and retains all rights under the PDPA.
You may withdraw consent at any time through your profile page or the contact channels in Section 18. Doing so may prevent you from using parts of the service.
5. Purposes of Use
We use your data to: create and verify user accounts; match and process bookings between users and caregivers; verify deposit and service payments; record and confirm caregivers' performance of work; send notifications relating to bookings, payments, and communications between users; prevent fraud and maintain system security; review inappropriate content against our community standards; resolve disputes; develop and improve service quality; and comply with the law and orders from competent authorities.
We do not use health data for advertising, marketing, or behavioural analysis for any purpose other than delivering care services, and we do not store personal health data in iCloud.
6. Permissions We Request on Your Device
Location (When In Use) — used to match you with nearby caregivers. The app reads your location on demand while in use and does not track in the background. You may refuse or withdraw this permission in your device settings and may enter an address manually instead
Camera and photo library — used to take or select a profile photo and proof of payment
Notifications — used to inform you of booking status, payments, and account notices. You may disable these in your device settings
Refusing any of the above permissions does not deprive you of core functions that do not depend on that permission.
7. Disclosure to Third Parties
We may disclose your data in the following circumstances.
A. The caregiver/partner you book with — only the information necessary to deliver the service, such as name, contact number, service address, and relevant health data (subject to consent under Section 4). Caregivers are obliged under the Terms of Service to keep such information confidential.
B. External service providers we use (data processors) — we have data processing agreements in place with every one of these providers so that your data receives the same level of protection as set out in this policy.
Provider · Purpose · Country of processing
DigitalOcean, LLC — Hosting of all application databases, files, and images · Singapore (SGP1 data centre)
Google Maps Platform (Google LLC) — Processing coordinates for matching, and displaying maps and routes · United States and other countries where Google operates
OneSignal, Inc. — Delivering push notifications to your device · United States
Thaibulksms (Triple S Advance Technology Co., Ltd.) — Sending OTP verification codes by SMS · Thailand
Firebase Crashlytics (Google LLC) — Detecting application errors and crashes · United States and other countries where Google operates
Note on health data: we do not transmit your health data, blood group, or national ID number to Google Maps Platform, OneSignal, Thaibulksms, or Firebase Crashlytics. Such data is stored and processed solely on DigitalOcean infrastructure as described in Section 8.
C. Government authorities — where required by law or court order.
D. Merger or transfer of business — in the event of a merger, sale, or transfer of the business, in which case we will notify you in advance through the application.
We do not sell your personal data to third parties for marketing purposes and do not share your data with any advertising network.
8. International Data Transfers
Your data is stored on DigitalOcean cloud infrastructure at its data centre in Singapore (SGP1), including the elderly person's health data and blood group, national ID numbers, work photographs, and chat messages. In addition, the other providers listed in Section 7 may process some data outside Thailand, except for SMS delivery, which is processed in Thailand.
Where data is transferred abroad, we comply with Section 28 of the PDPA by putting appropriate safeguards in place, namely:
Data Processing Agreements and Standard Contractual Clauses with every provider
Encryption at rest and encryption in transit
Restricting access to sensitive data to staff whose duties directly require it
We do not transmit your health data, blood group, or national ID number to any provider other than DigitalOcean, and we do not disclose such data to any foreign authority unless required by Thai law or a Thai court order.
9. Use of Google APIs
Our use of information received from Google APIs (including Google Maps Platform) complies with the Google API Services User Data Policy, including the Limited Use requirements.
10. Cookies, Tracking Technologies, and No Cross-App Tracking
The application uses basic technologies such as session tokens and analytics identifiers to secure your account, prevent abuse, remember your settings, and analyse usage in order to improve the service.
We do not track your behaviour across other companies' applications or websites (no cross-app tracking) and we do not share your data with advertising networks. We therefore do not request permission through App Tracking Transparency.
11. Chat Messages and User-Generated Content
Chat messages between you and caregivers, reviews, and images you upload are stored on our systems in order to provide the service, resolve disputes, and maintain security.
To protect users in line with our community standards, we use automated content screening together with review by staff only where content has been reported or where there are reasonable grounds to suspect a breach of the law or of the Terms of Service. The number of staff able to access such data is limited and they are bound by confidentiality obligations. We do not read your chat messages for marketing purposes.
12. Account Deletion and Data Retention
You can request deletion of your account yourself in the application at Profile → Settings → Delete account, without contacting our staff.
Once you confirm the request, we will suspend access to the account immediately and delete or anonymise your personal data within 30 days. Your phone number will be released so that it can be used to register again.
Health data, blood group, national ID number, chat messages, and work photographs are deleted at the end of the 30-day period and are not among the categories retained.
Certain categories of data must be retained for longer as required by law, as follows.
Data category · Retention period · Legal basis
Proof of payment and accounting records — 5 years · Revenue Code / Accounting Act
Booking and dispute records (excluding health data) — Up to 10 years, per the applicable limitation period · Legitimate interest in defending legal claims
Computer traffic data (logs) — 90 days · Computer Crime Act
Published reviews — Retained in anonymised form · Legitimate interest in platform trustworthiness
While your account remains active, we retain your data for as long as necessary to provide the service.
13. Data Security
We maintain appropriate technical and organisational measures to prevent unauthorised access, use, or disclosure, including encryption in transit and at rest, role-based access restrictions, and access logging — particularly for identity documents and health data.
Nevertheless, no method of transmission over the internet or system of electronic storage is 100% secure.
14. Personal Data Breach Notification
In the event of a personal data breach, we will notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it, so far as practicable. Where the breach poses a high risk to your rights and freedoms, we will notify you without delay together with our remedial measures, in accordance with Section 37(4) of the PDPA.
15. Minimum Age and Minors
The primary account holder must be at least 20 years of age and have the legal capacity to enter into a contract under Thai law.
We do not intend to collect personal data from minors without the parental consent required by law. If you become aware that a minor's data has been provided without appropriate consent, please notify us and we will investigate and delete such data promptly.
16. Rights of Data Subjects
You have the following rights under the PDPA.
Right of access and to obtain a copy of your personal data
Right to rectification of inaccurate or out-of-date data
Right to restrict processing of your data
Right to data portability — to have your data transferred to another data controller
Right to erasure or destruction of your data
Right to object to processing
Right to withdraw consent where processing relies on consent
Right to lodge a complaint with the Personal Data Protection Committee
You can manage some of this information yourself through your profile page, or contact us through the channels in Section 18 to exercise these rights. We will respond to your request within 30 days of receiving it.
17. Changes to This Policy
We may update this policy from time to time. The "Last updated" date above will reflect the most recent revision. Where a change is material, we will notify you through the application at least 30 days before the effective date, and where the change concerns sensitive data we will obtain fresh consent from you.
18. Contact Us
Data Controller: Mulberrysoft Co., Ltd. Telephone: 081-928-3243 (Monday–Friday, 9:00–18:00) Email: nat.sri@mulberrysoft.com
Reporting inappropriate content or conduct: through the report button in the application, or by email to nat.sri@mulberrysoft.com
If you are dissatisfied with the outcome of our handling of your request, you have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC).
19. Governing Language
Where this policy is translated into another language and there is any conflict or inconsistency between versions, the Thai version shall prevail.