Legal

Privacy Policy

Last updated: May 7, 2026

Bangkok Rock respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have under applicable data protection law, including the GDPR.

01

Who We Are

If you have questions about this Privacy Policy or how we process your personal data, please contact us at the email address below.

Data Controller

Bangkok Rock Ltd

615/9 Moo 7, Hin Lek Fai Sub-District

Hua Hin, Prachuap Khiri Khan, Thailand

CVR: Pending

persondata@bangkokrock.com
02

What Data We Collect

We may collect and process the following categories of personal data:

Order data

Name, billing address, shipping address, email address, phone number, purchased items, order value, shipping method, invoice details, and payment-related metadata. We do not store full payment card numbers.

Account data

If you create or use a customer account: email address, saved addresses, login-related information handled through Shopify, and order history.

Communication data

Records of messages and communications sent to us by email, contact form, chat, WhatsApp, SMS, or similar channels.

Technical data

IP address, browser type, device type, operating system, time of access, pages viewed, security events, and diagnostic or error logs. Shopify may process device, browser, IP, network, and browsing-related data in connection with its services.

Marketing and consent data

Consent preferences, newsletter sign-up details, and records showing when consent was given, changed, or withdrawn.

03

How We Collect Data

  • When you place an order with us.
  • When you contact us.
  • When you create or use a customer account.
  • When you browse or interact with our website.
  • When order, shipping, or marketplace information is provided through connected service providers such as Shopify, Sendcloud, or Amazon.
04

Why We Use Your Data

  • Operate, maintain, and secure our website and webshop.
  • Process orders, payments, shipping, returns, and refunds.
  • Manage customer accounts and customer service.
  • Communicate with you about your order, delivery, or support request.
  • Maintain internal business records and documentation.
  • Comply with legal, tax, accounting, and regulatory obligations.
  • Detect fraud, misuse, or technical abuse.
  • Improve our products, services, and website performance.
05

Legal Bases for Processing

Where GDPR applies, we process your personal data on one or more of the following legal bases:

Contract

Where processing is necessary to fulfill an order or take steps at your request before entering into a contract.

Legal obligation

Where we must retain or use data to comply with accounting, tax, consumer, or other legal requirements.

Legitimate interests

Where processing is necessary for the operation, security, administration, and improvement of our business, provided your rights do not override those interests.

Consent

Where required by law, for example for certain marketing activities or non-essential cookies. You may withdraw consent at any time.

06

Hosting and Internal Systems

Our online store is hosted on Shopify, which provides the e-commerce platform we use to sell our products and manage customer transactions. Shopify may process information such as IP address, device information, browser information, cookies, and browsing interactions, and may also process customer and order-related data in connection with store and checkout services.

In addition to Shopify, we also store and process relevant customer data in our own internal systems where necessary for customer service, order administration, internal recordkeeping, accounting, legal compliance, dispute handling, and protection of our legitimate business interests.

07

Who We Share Data With

We only share personal data where necessary for relevant business purposes and only to the extent required. We may share personal data with:

Shopify

Webshop hosting, checkout, customer account features, and order administration.

Sendcloud

Shipping, label creation, delivery processing, and logistics coordination. Sendcloud acts as a processor under our instructions.

Amazon

Where relevant for marketplace sales, order fulfillment, order management, and related customer service.

Communication & technology providers

Where used for messaging, hosting, diagnostics, support, databases, or related business operations.

Professional advisers & authorities

Where disclosure is required by law or reasonably necessary for legal, accounting, or regulatory purposes.

Where required, we use contractual safeguards such as data processing agreements with service providers acting on our behalf.

08

International Data Transfers

Because we use international service providers, your personal data may be processed in countries outside your own country and, where relevant, outside the European Economic Area. Sendcloud states that for certain services it may use processors or business partners outside the EU/EEA and relies on safeguards such as Standard Contractual Clauses where required.

Where legally required, we seek to ensure that appropriate safeguards are in place for international transfers.

09

How Long We Keep Data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.

5 years

Order & accounting data

In line with applicable bookkeeping and accounting requirements.

Active + reasonable period

Marketing consent records

Kept while consent is active and for a reasonable period afterward to document compliance.

As needed

Customer service & communications

Kept as long as reasonably necessary to handle the relevant matter.

Up to 30 days

Server logs

Unless needed longer for security purposes.

Up to 90 days

Error & diagnostic logs

Unless needed longer for investigation or documentation purposes.

10

Your Rights

Subject to applicable law, you may have the right to:

Access your personal data
Request correction of inaccurate data
Request deletion of your data
Request restriction of processing
Object to certain processing
Request data portability where applicable
Withdraw consent at any time
Lodge a complaint under Article 77 GDPR

To exercise your rights, email persondata@bangkokrock.com. Requests are generally answered within one month, subject to lawful extensions.

11

Cookies and Similar Technologies

We use cookies and similar technologies to operate the website, remember preferences, support store functionality, improve user experience, and understand how visitors use the site. Shopify uses cookies and similar technologies in connection with website and store interactions.

Where required by law, non-essential cookies will only be used with your consent. You can also control cookies through your browser settings.

12

Data Security

We use appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, misuse, or loss. However, no online service can be completely secure, and we cannot guarantee absolute security.

13

Third-Party Platforms

If you purchase through or otherwise interact with Bangkok Rock through a third-party platform such as Amazon, your personal data may also be processed under that platform's own terms and privacy policies.

We recommend reviewing the privacy policies of the third-party services you use when interacting with our business.

14

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. The latest version will always be posted on this page.

Questions about your data? persondata@bangkokrock.com

Privacy Policy — Bangkok Rock | Bangkok Rock Store