1. Who handles your information
AlphaBlue is responsible for personal data processed to market, sell, deliver, support, and administer AlphaBlue Website Service. You can contact us atsupport@alphablueth.com or at 187/50 Moo 5, Choeng Noen Subdistrict, Mueang Rayong District, Rayong Province 21000, Thailand.
This policy describes our own processing. A customer website may collect information from that customer's visitors after launch. The customer is responsible for deciding what its website collects and for publishing an appropriate notice for its own visitors. AlphaBlue may process that visitor information as a service provider when we host or operate an agreed feature.
2. Information we collect
Contact and account information
We may collect your name, business name, email address, phone number, LINE or other contact handle, preferred language, account identifiers, and authentication or security records.
Enquiry and order information
We collect package interests, selected add-ons, referral details, quote information, order and invoice references, transaction status, policy versions, and communications about payment, cancellation, refunds, or disputes.
Project materials
We process the business details, service descriptions, prices, hours, addresses, contact links, social channels, documents, logos, photos, videos, brand assets, customer instructions, and feedback needed to design and deliver the website.
Technical and usage information
Our systems may receive IP address, browser and device information, page and referral URL, timestamps, security logs, form events, portal activity, and records needed to prevent abuse or diagnose service problems.
Payment information
Stripe processes card and other payment-method details. AlphaBlue receives transaction references, payment status, amount, currency, limited customer details, refund information, and dispute information. We do not receive or store your complete card number.
For bank transfers and cash payments, we may collect the payer name and type, bank name or code, the last four digits of the source account, transfer reference, transfer slip, cash receipt, collection location, payment time, and the staff members who recorded and verified the payment. If you request an offline refund, we may also collect the destination account holder name, bank and account number, evidence of account ownership, exception reason, refund proof, and signed receipt. Full destination account numbers are stored in encrypted form and are masked in ordinary portal and operational views.
3. Where information comes from
We receive information:
- Directly from you through forms, checkout, the Customer Portal, email, live chat, phone, LINE, or meetings.
- From an employee or authorized partner assisting with your enquiry or project.
- From Stripe and other providers involved in payment, domain, email, hosting, security, or delivery.
- From social profiles, business listings, documents, or public channels that you identify or authorize us to use when preparing your website.
Please do not send sensitive personal data unless it is necessary for an agreed feature and we have confirmed an appropriate method for handling it.
4. How and why we use information
We use personal data to:
- Respond to enquiries, recommend a package, and prepare a quote.
- Create and administer orders, accounts, portal access, payments, invoices, refunds, and disputes.
- Verify offline payments, match an approved refund to the recorded payer, reconcile cash, and prevent payments to unauthorized third parties.
- Collect requirements, prepare V1 and V2 drafts, obtain approvals, publish the website, and provide support.
- Register or configure agreed domains, mailboxes, forms, analytics, and third-party services.
- Send service messages, security notices, delivery updates, and renewal reminders.
- Attribute an eligible referral and calculate related partner records.
- Secure our systems, prevent fraud and abuse, investigate incidents, and keep audit records.
- Comply with legal, tax, accounting, payment-network, and regulatory obligations.
- Improve our service using aggregated or appropriately limited operational information.
Depending on the activity and applicable law, we rely on steps requested before a contract, performance of a contract, legal obligations, consent, and legitimate interests such as service security, fraud prevention, support, and improvement. You may withdraw consent where processing relies on consent. Withdrawal does not affect processing already completed lawfully.
5. Information intended for your public website
Business information and materials approved for publication become publicly accessible after launch. Search engines, social platforms, archives, and visitors may copy or index public content. Removing content from the live website may not immediately remove copies held elsewhere.
You are responsible for confirming that you have the right to provide and publish submitted materials, including logos, photographs, testimonials, staff details, and information about other people. Tell us before publication if any supplied material is private, licensed with restrictions, or must not be indexed.
8. Retention and security
We keep information for as long as needed to handle the enquiry, perform and support the order, maintain security and audit records, establish or defend legal claims, and meet tax, accounting, payment, and regulatory requirements. Different records may therefore have different retention periods. When information is no longer required, we delete it, anonymize it, or restrict its use.
We use role-based access, authentication, audit records, encrypted connections, managed infrastructure, backups, and operational procedures appropriate to the information and risk. No online service can guarantee absolute security. Please contact us promptly if you believe your account, materials, or communications have been accessed improperly.
Offline-payment proofs and refund instructions are private operational records. Access is limited to authorized staff who need them for payment verification, refund execution, accounting, security, a dispute, or a legal obligation. Ordinary lists, notices, emails, and audit metadata use masked account details rather than a complete account number.
9. Your privacy rights
Subject to applicable law and relevant exceptions, you may ask to access, correct, receive, delete, restrict, or object to processing of your personal data. You may also withdraw consent where consent is the basis for processing and complain to the competent data protection authority.
Send a request to support@alphablueth.com. We may need to verify your identity and clarify the request. Certain order, payment, security, or legal records may need to be retained even after another part of your data is deleted.
10. Questions, complaints, and policy changes
Contact support@alphablueth.com with a privacy question or complaint. We will investigate and respond within the period required by applicable law.
We may update this policy when the service, providers, or legal requirements change. We will publish the updated effective date and version on this page. Material changes affecting an active customer relationship may also be communicated through the portal or the contact details on file.