Who this policy covers
Mindbase Corporation Co., Ltd. provides MindPOS and is responsible for data used to register accounts, communicate with users and operate the service. This policy covers the MindPOS website and app, including QR ordering at participating shops. It applies to shop owners, staff, contacts and customers whose personal data is handled through the service.
For customer and staff data entered by a shop, the shop determines its own purposes for using that data, and MindPOS processes it to provide the agreed service. Requests concerning a shop’s records may need to be coordinated with that shop.
Data we receive
We receive data you enter or upload, records entered by shop owners or authorised staff, information generated by website and app use, and responses from services a shop connects. The data involved depends on the features you use.
Accounts and contact details
Display name, username, phone number, email, authentication details, account identifiers, shop roles, language and sign-in history.
Shop operations
Shop name and type, address, shop coordinates, contacts, staff, menus, images, logos, inventory and saved settings.
Orders and payments
A customer’s name or nickname, phone number and contact details provided by the customer, shop or connected platform, table number, order items, notes, amounts, payment method and status, receipts, receiving-account or PromptPay details, and slip information submitted when transfer verification is used.
Devices and usage
IP address, device and browser type, session details, activity and error records, and printer connection settings you configure.
App Store subscriptions
When you purchase or restore a plan through Apple, we receive Apple-signed transaction evidence, transaction and original transaction identifiers, the product identifier, purchase and access-expiry dates, refund or revocation status, and an opaque shop account token. This purchase history is linked to your shop account to verify purchases, restore access, and prevent reuse across shops. Apple handles payment; MindPOS does not receive your card number or Apple Account payment-method details.
Location and referrals
Location you allow for setting a shop’s map pin or validating table ordering when enabled by the shop, and referral codes associated with shop applications.
Data needed for registration, authentication or transactions is necessary to complete those steps. Without it, some services may be unavailable. Please avoid including unnecessary personal or sensitive information in notes or uploaded files.
Why we use data
Deliver the requested service
Create and verify accounts, review shop applications, manage staff access, process orders and kitchen queues, issue receipts, verify payments, show reports and manage subscriptions, on a contractual or pre-contractual basis.
Operate and support the service
Send application and service updates, respond to support requests, investigate errors, prevent unauthorised access and fraud, and improve reliability, based on the service contract or legitimate interests balanced against your rights.
Meet legal duties
Keep accounting and transaction evidence, respond to lawful requests and handle disputes under applicable obligations.
Uses requiring consent
Where consent is required, such as for certain marketing communications, we request it for the relevant purpose. You may withdraw it. Reading this policy does not give consent to every use of your data.
Who receives data
Data may be accessed or shared as needed with the following recipients, according to enabled features and access permissions.
Shops and authorised users
Owners and staff access information allowed by their role, such as customer orders and shop reports. MindPOS staff use information needed for application review, service operation or support.
Technical providers
Hosting, database, file-storage, email or OTP providers, and error-monitoring services such as Sentry, to operate the service and investigate problems.
Feature providers
Examples include Slip2You for payment-slip verification, mapping and place-search services such as OpenStreetMap and Nominatim, and ordering platforms connected by a shop. These providers may have their own policies for processing for which they are responsible.
Apple for subscriptions
For In-App Purchase, we provide the product identifier and an opaque shop token to Apple to associate and verify transactions. Purchase, renewal and refund information from Apple is used to manage access. Apple Account and payment processing are governed by Apple’s policies.
Legally authorised recipients
Competent authorities or relevant parties where necessary for legal claims or preventing harm, within an appropriate scope.
Device permissions
Camera and image files
Used when you take or select an image, such as a payment slip, menu photo or logo. Submitted files are used for that feature.
Location
Used when you choose your current location to place a shop’s map pin, or verify location for QR ordering when the shop requires it. You can control permission in your browser or device settings.
Network and printers
The app may use local-network or device-connection permissions supported by your device to connect to the selected printer and send receipts or kitchen tickets.
You may deny or revoke permissions, although features that depend on them may not work. Revoking permission does not delete previously submitted data. Contact us below to request deletion.
Cookies and device storage
MindPOS uses cookies and browser or app storage for language preferences, sign-in, carts, table-ordering sessions and related settings. The language cookie lasts up to one year; a referral code saved in the browser expires after 30 days.
With consent, MindPOS collects UTM parameters, supported ad-click IDs, referrer domain, landing path, language, device category and a random visitor ID to measure signup steps and link campaign sources to registered shops and confirmed MindPOS package purchases for the internal System Console team. This measurement excludes form contents, passwords, OTPs and full URLs. Browser visitor IDs and events expire after 90 days; shop-linked attribution is retained for up to 400 days from first visit, with scheduled cleanup. Withdrawal stops new collection and removes the browser identifier; it does not automatically delete stored records. Contact us below to exercise data rights.
If you accept advertising measurement, the MindPOS website uses Meta Pixel to send page-visit events only on the home, plans, app-download and merchant-registration pages, and a completed-registration event only after account creation succeeds. This helps measure and improve advertising. We do not use Pixel in the POS, customer-ordering pages or the MindPOS native app.
Meta may receive the public page URL, event time, IP address, browser details and cookie or ad-click identifiers to associate activity with ads and Meta accounts under Meta’s policies, including processing outside Thailand. We do not send names, email addresses, phone numbers, shop names, passwords, OTPs, sign-in tokens, customer records, orders or sales values as event data. Advanced matching and automatic event tracking are disabled.
Advertising measurement is optional and is not required to sign up or use MindPOS. Meta Pixel is not loaded before consent. You can change or withdraw consent using ‘Advertising cookie settings’ on public marketing pages and this policy page. We remember your choice in the browser for 180 days. Withdrawing consent stops new events without clearing the form you are completing. Withdrawal does not delete data previously sent to Meta.
You can clear this data in device or browser settings. Doing so may sign you out or remove unsubmitted items. Clearing local data or uninstalling the app does not delete your account or shop records held by the service.
Retention and deletion
Retention depends on how long you or your shop use the service, the needs of transactions and support, applicable limitation periods and legal record-keeping duties. Periods vary by data type. Cancelling a subscription or stopping app use does not immediately delete shop records.
Precise coordinates used for table-ordering location checks have a 30-day retention period and are removed in a subsequent cleanup run. Verification history without those coordinates may remain. This period does not apply to the shop location you save for ongoing use.
When data is no longer needed and no retention duty applies, we will delete, destroy or anonymise it as appropriate. If a deletion request involves records still needed by law or for a dispute, we will explain why and what must be retained. Contact us for retention details about your records.
International processing
Infrastructure and other service providers may process data outside Thailand. Where international transfers occur, we will follow applicable data-protection requirements, including relevant safeguards or agreements. You can request details about transfers relating to your use of the service through the contact channels below.
Security
The system controls access by account and shop role, uses authentication and session management, and records events to support investigations. Keep passwords and OTPs confidential, assign appropriate staff access, and sign out when using a shared device.
If a data breach occurs, we will assess it and fulfil applicable legal duties. Where notification is required, this includes notifying Thailand’s Personal Data Protection Committee Office without delay and, where feasible, within 72 hours of awareness, and notifying affected individuals without delay with remedial information if there is a high risk to their rights and freedoms.
Your rights and requests
Subject to legal conditions and exceptions, you may request access and copies, correction, portability, objection or restriction, deletion or anonymisation, and withdrawal of consent for consent-based processing. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise your rights or request account and personal-data deletion, contact us below with the relevant account or shop and your request. We may ask for necessary identity verification and coordinate with the shop. We will communicate the outcome or reasons for any refusal within applicable legal time limits. You may complain to Thailand’s Personal Data Protection Committee Office if you believe processing violates the law.
Minors
MindPOS shop-management services are designed for business operators and users authorised by their shops. Where processing concerns a minor or a person with limited legal capacity and requires consent, consent must be obtained from the legally authorised person as required by law. Contact us if you believe data has been provided without meeting these requirements so we can investigate and take appropriate action.
Policy updates
We may update this policy as the service or applicable requirements change. The current version and update date appear on this page. We will communicate material changes through appropriate service channels and obtain new consent where required by law.
Privacy contact
For policy questions, rights requests, or account and personal-data deletion requests, contact:
Mindbase Corporation Co., Ltd.support@mindbase.co.th066-164-45369 Pracharat Sai 2 Road, Bang Sue, Bang Sue, Bangkok 10800, Thailand
Contact LINE @mindposInclude your request and the relevant account or shop. Do not send passwords or OTPs.