TookJorThai · ทุกจอไทย
นโยบายความเป็นส่วนตัว
Privacy Policy
Last updated: อัปเดตล่าสุด:
ภาษาไทย
1. ผู้ให้บริการและช่องทางติดต่อ
นโยบายนี้อธิบายวิธีที่ TookJorThai / ทุกจอไทย เก็บ ใช้ เปิดเผย และดูแลข้อมูลส่วนบุคคล จากการใช้เว็บไซต์ บัญชีผู้ใช้ ระบบซื้อ Token หรือเครดิต การชำระเงิน Desktop Application, Chrome Extension, OCR, การแปลข้อความ การแปลไฟล์หรือเกม และช่องทางสนับสนุนลูกค้า
TookJorThai / ทุกจอไทย 91/454 ม.9 ซ.16/3 ต.ต้นเปา อ.สันกำแพง จ.เชียงใหม่ 50130 097-047-9817 support@tookjorthai.com ทุกจอไทยหากต้องการใช้สิทธิหรือยื่นคำร้องเกี่ยวกับข้อมูลส่วนบุคคล กรุณาติดต่อผ่าน Facebook Fanpage อย่างเป็นทางการ อีเมล หรือโทรศัพท์ตามข้อมูลข้างต้น
2. ขอบเขตของนโยบาย
นโยบายนี้ครอบคลุมบริการ TookJorThai ทั้งหมดที่เชื่อมกับระบบของเรา รวมถึงเว็บไซต์ บัญชีสมาชิก การเข้าสู่ระบบ การซื้อ Token/เครดิต การชำระเงินผ่านผู้ให้บริการรับชำระเงิน แอป Desktop, Chrome Extension, ระบบ OCR, ระบบแปลข้อความ ระบบแปลไฟล์หรือเกม ระบบเสียง/ประชุม และการติดต่อฝ่ายสนับสนุน
3. ประเภทข้อมูลที่เก็บหรือประมวลผล
ข้อมูลที่ระบบอาจเก็บหรือประมวลผล แยกตามหลักฐานที่พบในโค้ด มีดังนี้:
- ข้อมูลบัญชีและข้อมูลติดต่อ: อีเมล ชื่อผู้ใช้หรือชื่อที่แสดง รหัสผู้ใช้ สถานะบัญชี บทบาทผู้ใช้ สถานะยืนยันอีเมล รหัสผ่านในรูปแบบ hash, refresh token ในรูปแบบ hash, OTP ในรูปแบบ hash และวันหมดอายุที่เกี่ยวข้อง
- ข้อมูลธุรกรรมและการชำระเงิน: แพ็กเกจหรือเครดิตที่ซื้อ จำนวนเงิน สกุลเงิน วันเวลา สถานะคำสั่งซื้อ วิธีชำระเงิน หมายเลขคำสั่งซื้อ หมายเลข Omise charge/source/webhook reference สถานะคืนเงิน จำนวนเงินที่คืน และเหตุผลความล้มเหลวเท่าที่ระบบได้รับจากผู้ให้บริการรับชำระเงิน
- เนื้อหาที่ผู้ใช้ส่งมาเพื่อประมวลผล: ข้อความที่ต้องการแปล ข้อความจาก OCR รูปภาพ base64 สำหรับ Cloud OCR ไฟล์หรือข้อมูลเกมที่ใช้สร้างแพตช์ ไฟล์เสียง/ข้อมูลการประชุม และข้อมูลบริบทที่ผู้ใช้หรือแอปส่งมาเพื่อช่วยแปล
- ข้อมูลการใช้งานและ Token: ประวัติ ledger ของเครดิต/Token ยอดคงเหลือ การหัก/คืนเครดิต ฟีเจอร์ที่ใช้ จำนวนตัวอักษร จำนวนภาพ/ช่วงเวลา สถานะงาน Job ID ผลลัพธ์บางส่วนของงานแปล ข้อผิดพลาด และข้อมูล cache ที่ช่วยลดการเรียกผู้ให้บริการซ้ำ
- ข้อมูลอุปกรณ์และข้อมูลทางเทคนิค: Device ID เมื่อระบบส่งมา, User Agent หรือ IP address ใน log บางจุด เช่น webhook/security log, request id, วันเวลาใช้งาน, URL หรือ page URL ที่ส่งมาพร้อมคำขอ OCR/translation และ log เพื่อแก้ปัญหา
- การตั้งค่าภายในเครื่อง:
Access token และ refresh token บนเว็บไซต์เก็บใน
localStorage; return path บางรายการเก็บในsessionStorage; Chrome Extension เก็บ Bridge URL, Session Token, Pairing Token, สถานะเชื่อมต่อ, ค่าโหมด OCR/DOM/TTS และค่าการแสดงผลในchrome.storage.localบนอุปกรณ์ของผู้ใช้ - ข้อมูลติดต่อฝ่ายบริการ: ข้อความที่ลูกค้าส่ง หลักฐานการชำระเงิน ภาพหน้าจอ Job ID หมายเลขรายการ และข้อมูลที่จำเป็นต่อการตรวจสอบบัญชีหรือแก้ไขปัญหา
- Cookie และ Analytics: จากโค้ด frontend และ browser extension ที่ตรวจสอบ ไม่พบ Google Analytics, Firebase Analytics, advertising pixel หรือ tracking cookie สำหรับโฆษณา/สร้างโปรไฟล์ผู้ใช้
ข้อมูลบางส่วนเก็บบน server ของ TookJorThai เช่น บัญชี ธุรกรรม ledger งานแปล cache และ log; ข้อมูลบางส่วนเก็บในอุปกรณ์ของผู้ใช้ เช่น localStorage, sessionStorage และ chrome.storage.local; และข้อมูลบางส่วนถูกส่งให้ผู้ให้บริการภายนอกเฉพาะเมื่อจำเป็นต่อการให้บริการ
4. วัตถุประสงค์ในการใช้ข้อมูล
- สร้าง ดูแล และยืนยันบัญชีผู้ใช้
- ให้บริการแปลข้อความ OCR ไฟล์ เกม เสียง และข้อมูลการประชุม
- คำนวณ หัก เพิ่ม และคืน Token/เครดิต
- ประมวลผล ตรวจสอบ และกระทบยอดการชำระเงินหรือการคืนเงิน
- ป้องกันการฉ้อโกง การใช้สิทธิ์ซ้ำ การโจมตี webhook และการใช้งานผิดปกติ
- แก้ไขข้อผิดพลาด ดูแลความปลอดภัย และปรับปรุงเสถียรภาพของบริการ
- ให้บริการลูกค้าและตรวจสอบคำร้อง
- ปฏิบัติตามกฎหมาย บัญชี ภาษี การตรวจสอบ และการจัดการข้อพิพาท
- ปรับปรุงคุณภาพบริการจากข้อมูลที่จำเป็น เช่น cache, usage log และ feedback
5. การเปิดเผยและส่งข้อมูลให้บุคคลภายนอก
เราแบ่งปันข้อมูลเฉพาะเท่าที่จำเป็นกับผู้รับข้อมูลต่อไปนี้:
- Omise: เพื่อสร้าง charge/source, ตรวจสอบ payment, webhook, refund และ dispute
- ผู้ให้บริการแปลหรือ AI ที่พบใน config: Google Gemini, OpenTyphoon, OpenAI และ Soniox สำหรับเสียง/ถอดเสียงตามฟีเจอร์ที่เปิดใช้
- Google Cloud Vision: เมื่อผู้ใช้ใช้ Cloud OCR หรือระบบ route ไปยัง Cloud OCR ที่เปิดใช้งาน
- ระบบฐานข้อมูล/คิว/โฮสติ้ง: MongoDB, Redis/BullMQ, local storage driver และ Firebase Hosting สำหรับเว็บไซต์ตาม configuration ที่พบ
- Gmail SMTP: สำหรับส่งอีเมล OTP/ยืนยันบัญชีเมื่อมีการตั้งค่า
- ผู้ให้บริการสนับสนุนทางเทคนิคหรือหน่วยงานรัฐ: เมื่อจำเป็นต่อการแก้ไขปัญหา ปฏิบัติตามกฎหมาย หรือจัดการข้อพิพาท
TookJorThai ไม่ขายข้อมูลส่วนบุคคล ไม่ส่งข้อมูลให้ผู้โฆษณาเพื่อสร้างโปรไฟล์ผู้ใช้ และไม่ใช้ข้อมูลเพื่อประเมินเครดิตหรือการให้สินเชื่อ
สำหรับการชำระเงินผ่านบัตร ระบบ backend ของ TookJorThai รับเฉพาะ Omise token
เช่น tokn_... ที่ออกโดย Omise.js และปฏิเสธ raw card number, CVC/CVV หรือวันหมดอายุ
ผ่าน validation ของ backend ตาม implementation ที่ตรวจพบ
6. การส่งข้อมูลไปต่างประเทศ
ผู้ให้บริการบางราย เช่น Omise, Google, OpenTyphoon, OpenAI, Soniox, ผู้ให้บริการฐานข้อมูล คลาวด์ หรือโฮสติ้ง อาจประมวลผลหรือจัดเก็บข้อมูลนอกประเทศไทย เราจะส่งข้อมูลเท่าที่จำเป็นต่อบริการและใช้มาตรการที่เหมาะสมตามสัญญา นโยบายของผู้ให้บริการ และกฎหมายที่เกี่ยวข้อง
7. ระยะเวลาจัดเก็บข้อมูล
| ประเภทข้อมูล | ระยะเวลาจัดเก็บ |
|---|---|
| ข้อมูลบัญชี | ตลอดระยะเวลาที่บัญชียังเปิดใช้งาน และจนกว่าคำขอลบบัญชีจะดำเนินการเสร็จ เว้นแต่ต้องเก็บต่อเพื่อกฎหมาย บัญชี ภาษี การตรวจสอบ หรือข้อพิพาท |
| Refresh token | ลบอัตโนมัติตาม expiresAt ผ่าน MongoDB TTL index; ค่าเริ่มต้นของ access token คือ 15 นาที และ refresh token คือ 30 วันตาม config |
| Email OTP | ลบอัตโนมัติตาม expiresAt ผ่าน MongoDB TTL index; ค่าเริ่มต้น OTP คือ 10 นาทีตาม config |
| งานแปลแบบ async/post-process | ลบอัตโนมัติหลัง 14 วันตาม TTL index ของ translation_jobs |
| ธุรกรรมและ billing audit log | ไม่มี TTL ใน schema ที่ตรวจพบ และเก็บเป็น system-of-record เพื่อบัญชี ภาษี การตรวจสอบ refund/chargeback และข้อพิพาท |
| Credit/Token ledger | ไม่มีวันหมดอายุของเครดิต และ ledger เป็น source of truth ของยอดคงเหลือ จึงเก็บไว้ตราบเท่าที่จำเป็นต่อบัญชี การตรวจสอบ และข้อพิพาท |
| Translation/TTS/Speech cache | เก็บเท่าที่จำเป็นต่อการให้บริการ cache และคุณภาพบริการ; ไม่พบ TTL อัตโนมัติใน schema ที่ตรวจสอบ |
| Cloud OCR image bytes | ตาม controller ที่ตรวจพบ image bytes ไม่ถูก persist โดย endpoint Cloud Vision; log เก็บ metadata เช่นขนาด จำนวนผลลัพธ์ เวลา และ context ที่ส่งมา |
| Meeting/audio/file/game processing | เก็บตามระยะเวลาที่จำเป็นต่อการประมวลผล ดาวน์โหลด ตรวจสอบ และ support; บาง schema มี soft delete แต่ไม่พบ TTL อัตโนมัติทั่วไป |
| การตั้งค่าใน browser/extension | อยู่ในอุปกรณ์ของผู้ใช้จนกว่าผู้ใช้ล้างข้อมูล ออกจากระบบ หรือถอนการติดตั้ง Extension |
| Support request | จนกว่าคำร้องเสร็จสิ้น และต่อไปเท่าที่จำเป็นต่อการตรวจสอบข้อพิพาท การชำระเงิน หรือการใช้สิทธิ |
| Security/application logs | ตามการตั้งค่าปฏิบัติการจริงของระบบ log; ไม่พบ retention job กลางที่ระบุจำนวนวันสำหรับ log ทุกประเภทในโค้ดที่ตรวจสอบ |
8. สิทธิของเจ้าของข้อมูล
เท่าที่กฎหมายที่เกี่ยวข้องกำหนด ผู้ใช้อาจมีสิทธิดังต่อไปนี้:
- ขอเข้าถึงข้อมูล ขอสำเนาข้อมูล หรือขอรับ/โอนข้อมูลในกรณีที่ใช้สิทธิได้
- ขอแก้ไขข้อมูลให้ถูกต้อง
- ขอลบ ทำลาย หรือจำกัดการใช้ข้อมูล
- คัดค้านการประมวลผล หรือถอนความยินยอมเมื่อฐานการประมวลผลคือความยินยอม
- ร้องเรียนต่อหน่วยงานที่มีอำนาจ
ขั้นตอนยื่นคำร้อง: ติดต่อผ่าน Facebook Fanpage อีเมล หรือโทรศัพท์ แจ้งอีเมลหรือรหัสบัญชี ระบุประเภทคำร้อง และส่งข้อมูลที่จำเป็นต่อการยืนยันตัวตน ผู้ให้บริการจะตรวจสอบตัวตนก่อนดำเนินการ และตั้งเป้าตอบรับหรือดำเนินการภายใน 30 วัน นับจากวันที่ได้รับข้อมูลและยืนยันตัวตนครบถ้วน เว้นแต่กฎหมายอนุญาตให้ขยายเวลา
ข้อมูลบางประเภทอาจลบไม่ได้ทันทีหากจำเป็นต่อกฎหมาย บัญชี ภาษี การป้องกันการฉ้อโกง การตรวจสอบการชำระเงิน การจัดการข้อพิพาท หรือการใช้สิทธิ/ป้องกันสิทธิเรียกร้อง รายละเอียดเพิ่มเติมเกี่ยวกับการลบบัญชีและข้อมูลอยู่ใน นโยบายการยกเลิกและคืนเงิน
9. Cookie และระบบติดตาม
จากโค้ดเว็บไซต์และ Extension ที่ตรวจสอบ ไม่พบ Google Analytics, Firebase Analytics, advertising pixel หรือ cookie เพื่อโฆษณา/สร้างโปรไฟล์ผู้ใช้ จึงยังไม่จำเป็นต้องมี cookie consent banner สำหรับ tracking ที่ไม่จำเป็น หากในอนาคตมีการเพิ่ม analytics หรือ tracking ที่ต้องอาศัยความยินยอม TookJorThai จะต้องแสดงตัวเลือกยอมรับ ปฏิเสธ ตั้งค่า และถอนความยินยอมโดยไม่ติ๊กยินยอมล่วงหน้า
10. ความปลอดภัย
ระบบใช้มาตรการทั่วไป เช่น การยืนยันตัวตนด้วย JWT/OTP, hash รหัสผ่านและ token บางประเภท, การจำกัดสิทธิ์เข้าถึงข้อมูล, validation เพื่อปฏิเสธข้อมูลที่ไม่ควรรับ เช่นเลขบัตรเต็ม, HTTPS/การเข้ารหัสระหว่างส่งเมื่อใช้งานผ่าน production endpoint, request/security log, webhook verification และการตรวจสอบเหตุการณ์ผิดปกติ ทั้งนี้เราไม่เปิดเผยรายละเอียดเชิงลึกที่อาจกระทบความปลอดภัย
11. เงื่อนไขการใช้เครดิต (Token) และการผูกกับบัญชีผู้ใช้
เครดิต (Token) ที่ได้รับจากการซื้อ การเติม การแลกโค้ด หรือการได้รับสิทธิ์ใด ๆ ผูกกับบัญชีผู้ใช้ที่ทำรายการเท่านั้น และมีเงื่อนไขดังนี้
- ห้ามโอนเครดิต (Token) ไปยังบัญชีผู้ใช้รายอื่น ไม่ว่าทั้งหมดหรือบางส่วน ไม่ว่าจะโดยการขาย แลกเปลี่ยน ให้ หรือวิธีการอื่นใด
- ผู้ใช้สามารถใช้งานเครดิต (Token) ได้เฉพาะภายใต้บัญชีของตนเองเท่านั้น ระบบไม่มีฟังก์ชันสำหรับโอนหรือย้ายเครดิตระหว่างบัญชี
- เครดิต (Token) ไม่สามารถแลกเปลี่ยนเป็นเงินสด และไม่สามารถโอนสิทธิ์ให้บุคคลอื่นได้
- หากตรวจพบการซื้อขาย โอน หรือใช้เครดิตข้ามบัญชี เราขอสงวนสิทธิ์ในการระงับการใช้งาน ยกเลิกเครดิตส่วนที่เกี่ยวข้อง หรือระงับบัญชีที่เกี่ยวข้อง
ข้อมูลการใช้เครดิตจะถูกบันทึกใน ledger ของบัญชีผู้ใช้ตามที่ระบุในข้อ 3 และข้อ 7 เพื่อใช้ตรวจสอบยอดคงเหลือ การหัก/คืนเครดิต และการตรวจสอบข้อพิพาท
English
1. Service Provider and Contact Details
This Privacy Policy explains how TookJorThai / ทุกจอไทย collects, uses, discloses, and manages personal data across the website, user accounts, Token or credit purchases, payments, desktop application, Chrome Extension, OCR, text translation, file/game translation, voice/meeting features, and customer support.
TookJorThai / ทุกจอไทย 91/454 Moo 9, Soi 16/3, Ton Pao Subdistrict, San Kamphaeng District, Chiang Mai 50130, Thailand 097-047-9817 support@tookjorthai.com TookJorThaiPersonal-data requests may be submitted through the official Facebook Fanpage, email, or phone.
2. Scope
This Policy covers TookJorThai services connected to our systems, including the website, account login, Token/credit purchases, payment processing, desktop application, Chrome Extension, OCR, text translation, file/game translation, voice/meeting services, and support channels.
3. Data We Collect or Process
- Account and contact data: email, display name, user ID, account status, role, email-verification status, password hash, refresh-token hash, OTP hash, and related expiry timestamps.
- Transaction and payment data: purchased plan or credit pack, amount, currency, timestamp, order status, payment method, order number, Omise charge/source/webhook references, refund status, refunded amount, and payment failure reason where provided.
- User-submitted content: text for translation, OCR text, base64 image data for Cloud OCR, game/file data used for patch processing, audio/meeting data, and context sent to support translation.
- Usage and Token data: credit/Token ledger, balance, debit/refund/grant records, feature used, character counts, capture counts, duration, job status, Job ID, partial translation output, errors, and cache data.
- Device and technical data: Device ID where provided, User Agent or IP address in selected logs such as webhook/security logs, request ID, timestamps, page URL or URL context sent with OCR/translation requests, and troubleshooting logs.
- Local settings: website access and refresh tokens in
localStorage, return path insessionStorage, and Chrome Extension settings such as Bridge URL, Session Token, Pairing Token, connection state, OCR/DOM/TTS mode, and display settings inchrome.storage.local. - Support data: messages, payment evidence, screenshots, Job ID, order/reference numbers, and information needed to verify the account or resolve an issue.
- Cookies and analytics: based on the reviewed frontend and extension code, we did not find Google Analytics, Firebase Analytics, advertising pixels, or advertising/profile tracking cookies.
Some data is stored on TookJorThai servers, some remains on the user's device, and some is sent to external providers only when necessary to provide the service.
4. Purposes
- Create, maintain, and verify user accounts
- Provide text, OCR, file, game, voice, and meeting translation services
- Calculate, debit, grant, and refund Token/credit balances
- Process, verify, reconcile, and refund payments
- Prevent fraud, repeated claims, webhook attacks, and abnormal usage
- Fix errors, maintain security, and improve reliability
- Provide customer support and verify requests
- Comply with law, accounting, tax, audit, and dispute obligations
- Improve service quality using necessary cache, usage log, and feedback data
5. Disclosure and Recipients
- Omise: for charge/source creation, payment verification, webhooks, refunds, and disputes.
- Translation and AI providers found in configuration: Google Gemini, OpenTyphoon, OpenAI, and Soniox for voice/transcription features where enabled.
- Google Cloud Vision: when Cloud OCR is used or routed to the enabled Cloud OCR feature.
- Database, queue, storage, and hosting systems: MongoDB, Redis/BullMQ, local storage driver, and Firebase Hosting for the website as found in configuration.
- Gmail SMTP: for OTP or account-verification email when configured.
- Technical support providers or authorities: where necessary for troubleshooting, legal compliance, or disputes.
TookJorThai does not sell personal data, does not provide personal data to advertisers for user profiling, and does not use personal data to assess creditworthiness or lending eligibility.
For card payments, the TookJorThai backend accepts only Omise tokens such as tokn_...
issued by Omise.js and rejects raw card numbers, CVC/CVV, or expiry fields at the backend validation boundary.
6. International Transfers
Providers such as Omise, Google, OpenTyphoon, OpenAI, Soniox, database, cloud, or hosting providers may process or store data outside Thailand. We send only data necessary for the service and rely on appropriate contractual, provider-policy, and legal safeguards.
7. Retention
| Data Type | Retention |
|---|---|
| Account data | While the account remains active and until an account-deletion request is completed, unless further retention is required for legal, accounting, tax, audit, or dispute purposes. |
| Refresh tokens | Automatically deleted at expiresAt through a MongoDB TTL index; default access token lifetime is 15 minutes and refresh token lifetime is 30 days in configuration. |
| Email OTP | Automatically deleted at expiresAt through a MongoDB TTL index; default OTP lifetime is 10 minutes in configuration. |
| Async/post-process translation jobs | Automatically deleted after 14 days through the translation_jobs TTL index. |
| Transactions and billing audit logs | No TTL was found in the reviewed schema; retained as accounting/audit records for refunds, chargebacks, tax, and disputes. |
| Credit/Token ledger | Credits do not expire, and the ledger is the source of truth for balances; retained as necessary for account, audit, and dispute handling. |
| Translation/TTS/Speech cache | Retained as necessary for cache and service quality; no automatic TTL was found in the reviewed schemas. |
| Cloud OCR image bytes | The reviewed Cloud Vision endpoint states that image bytes are not persisted; logs keep metadata such as size, item count, timing, and request context. |
| Meeting/audio/file/game processing data | Retained as necessary for processing, download, audit, and support; some schemas include soft delete, but no general automatic TTL was found. |
| Browser/extension local settings | Remain on the user's device until the user clears data, signs out, or uninstalls the Extension. |
| Support requests | Retained until the request is resolved and thereafter as necessary for disputes, payment verification, and legal claims. |
| Security/application logs | According to actual operations settings; no central retention job with a fixed number of days was found for all log types. |
8. Data Subject Rights
To the extent provided by applicable law, users may request access, a copy, correction, deletion, restriction, objection, withdrawal of consent, data portability where applicable, and may lodge a complaint with a competent authority.
To submit a request, contact us via the official Facebook Fanpage, email, or phone, provide the account email or user ID, specify the request type, and provide information needed to verify identity. We will verify identity before processing and aim to respond or act within 30 days after receiving complete information and identity verification, unless an extension is permitted by law.
Some data may not be deleted immediately where it is needed for legal compliance, accounting or tax, fraud prevention, payment verification, disputes, or legal claims. Account and data deletion details are in the Cancellation and Refund Policy.
9. Cookies and Tracking
Based on the reviewed website and Extension code, we did not find Google Analytics, Firebase Analytics, advertising pixels, or advertising/profile tracking cookies. A tracking-consent banner is therefore not required for non-essential tracking at this time. If analytics or tracking requiring consent is added later, TookJorThai must provide accept, reject, settings, and withdrawal controls without pre-ticked consent.
10. Security
We use general safeguards such as JWT/OTP authentication, hashing of passwords and selected tokens, access control, validation that rejects data we should not receive such as full card data, HTTPS/encryption in transit on production endpoints, request/security logs, webhook verification, and incident monitoring. We do not disclose sensitive implementation details that could weaken security.
11. Credit (Token) Use and Account Binding
Credits (Tokens) obtained through purchase, top-up, code redemption, or any grant are bound to the user account that acquired them, subject to the following terms:
- Transferring credits (Tokens) to another user account is prohibited, whether in whole or in part, and whether by sale, exchange, gift, or any other means.
- Credits (Tokens) may be used only within the account holder's own account. The service provides no function to transfer or migrate credits between accounts.
- Credits (Tokens) are not redeemable for cash and the rights attached to them are not assignable.
- If we detect the sale, transfer, or cross-account use of credits, we reserve the right to suspend usage, revoke the affected credits, or suspend the accounts involved.
Credit usage is recorded in the account ledger described in Sections 3 and 7 for balance verification, deduction/refund tracking, and dispute resolution.