Legal
Privacy Policy
Last updated: May 7, 2026
Bangkok Rock respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have under applicable data protection law, including the GDPR.
Who We Are
If you have questions about this Privacy Policy or how we process your personal data, please contact us at the email address below.
Data Controller
Bangkok Rock Ltd
615/9 Moo 7, Hin Lek Fai Sub-District
Hua Hin, Prachuap Khiri Khan, Thailand
CVR: Pending
persondata@bangkokrock.comWhat Data We Collect
We may collect and process the following categories of personal data:
Order data
Name, billing address, shipping address, email address, phone number, purchased items, order value, shipping method, invoice details, and payment-related metadata. We do not store full payment card numbers.
Account data
If you create or use a customer account: email address, saved addresses, login-related information handled through Shopify, and order history.
Communication data
Records of messages and communications sent to us by email, contact form, chat, WhatsApp, SMS, or similar channels.
Technical data
IP address, browser type, device type, operating system, time of access, pages viewed, security events, and diagnostic or error logs. Shopify may process device, browser, IP, network, and browsing-related data in connection with its services.
Marketing and consent data
Consent preferences, newsletter sign-up details, and records showing when consent was given, changed, or withdrawn.
How We Collect Data
- When you place an order with us.
- When you contact us.
- When you create or use a customer account.
- When you browse or interact with our website.
- When order, shipping, or marketplace information is provided through connected service providers such as Shopify, Sendcloud, or Amazon.
Why We Use Your Data
- Operate, maintain, and secure our website and webshop.
- Process orders, payments, shipping, returns, and refunds.
- Manage customer accounts and customer service.
- Communicate with you about your order, delivery, or support request.
- Maintain internal business records and documentation.
- Comply with legal, tax, accounting, and regulatory obligations.
- Detect fraud, misuse, or technical abuse.
- Improve our products, services, and website performance.
Legal Bases for Processing
Where GDPR applies, we process your personal data on one or more of the following legal bases:
Where processing is necessary to fulfill an order or take steps at your request before entering into a contract.
Where we must retain or use data to comply with accounting, tax, consumer, or other legal requirements.
Where processing is necessary for the operation, security, administration, and improvement of our business, provided your rights do not override those interests.
Where required by law, for example for certain marketing activities or non-essential cookies. You may withdraw consent at any time.
Hosting and Internal Systems
Our online store is hosted on Shopify, which provides the e-commerce platform we use to sell our products and manage customer transactions. Shopify may process information such as IP address, device information, browser information, cookies, and browsing interactions, and may also process customer and order-related data in connection with store and checkout services.
In addition to Shopify, we also store and process relevant customer data in our own internal systems where necessary for customer service, order administration, internal recordkeeping, accounting, legal compliance, dispute handling, and protection of our legitimate business interests.
Who We Share Data With
We only share personal data where necessary for relevant business purposes and only to the extent required. We may share personal data with:
Shopify
Webshop hosting, checkout, customer account features, and order administration.
Sendcloud
Shipping, label creation, delivery processing, and logistics coordination. Sendcloud acts as a processor under our instructions.
Amazon
Where relevant for marketplace sales, order fulfillment, order management, and related customer service.
Communication & technology providers
Where used for messaging, hosting, diagnostics, support, databases, or related business operations.
Professional advisers & authorities
Where disclosure is required by law or reasonably necessary for legal, accounting, or regulatory purposes.
Where required, we use contractual safeguards such as data processing agreements with service providers acting on our behalf.
International Data Transfers
Because we use international service providers, your personal data may be processed in countries outside your own country and, where relevant, outside the European Economic Area. Sendcloud states that for certain services it may use processors or business partners outside the EU/EEA and relies on safeguards such as Standard Contractual Clauses where required.
Where legally required, we seek to ensure that appropriate safeguards are in place for international transfers.
How Long We Keep Data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.
5 years
Order & accounting data
In line with applicable bookkeeping and accounting requirements.
Active + reasonable period
Marketing consent records
Kept while consent is active and for a reasonable period afterward to document compliance.
As needed
Customer service & communications
Kept as long as reasonably necessary to handle the relevant matter.
Up to 30 days
Server logs
Unless needed longer for security purposes.
Up to 90 days
Error & diagnostic logs
Unless needed longer for investigation or documentation purposes.
Your Rights
Subject to applicable law, you may have the right to:
To exercise your rights, email persondata@bangkokrock.com. Requests are generally answered within one month, subject to lawful extensions.
Cookies and Similar Technologies
We use cookies and similar technologies to operate the website, remember preferences, support store functionality, improve user experience, and understand how visitors use the site. Shopify uses cookies and similar technologies in connection with website and store interactions.
Where required by law, non-essential cookies will only be used with your consent. You can also control cookies through your browser settings.
Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, misuse, or loss. However, no online service can be completely secure, and we cannot guarantee absolute security.
Third-Party Platforms
If you purchase through or otherwise interact with Bangkok Rock through a third-party platform such as Amazon, your personal data may also be processed under that platform's own terms and privacy policies.
We recommend reviewing the privacy policies of the third-party services you use when interacting with our business.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. The latest version will always be posted on this page.
Questions about your data? persondata@bangkokrock.com