Privacy Policy
Effective: 2026-09-22
CEONEQ is operated by IQX COMPANY LIMITED ("we", "us"). This policy explains how we collect, use, disclose and protect personal data when you use the CEONEQ website, application, APIs and platform integrations (the "Service"), in accordance with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA").
1. Our role
For account, contact and service-usage data we are the data controller.
For personal data of buyers or other individuals contained in a customer's store data (for example, order records), the customer who owns the store is the data controller. We process that data as a data processor, only on the customer's instructions and only to provide the Service.
2. Data we collect
- Account and contact data: name, email, phone number (if provided), organization or business name, and your role. Sign-in is handled by our identity provider; we do not store your password.
- Data from accounts you connect: when you authorize access through a platform's official API (for example TikTok Shop, TikTok for Business or Shopee), we may receive shop profiles, products and SKUs, orders, returns and refunds, fees, settlements and payouts, promotions, ad account and campaign performance, and creator/affiliate collaboration data, limited to the permissions you grant.
- Buyer data within orders: we request and retain only what is necessary to compute order economics and reconcile settlements. We do not use buyer data for marketing, do not profile individual buyers, and do not sell it.
- Business data you provide: cost of goods (COGS), packaging and shipping costs, and the policies and guardrails that control automation.
- Usage and technical data: system logs, IP address, device and browser type, timestamps and security events.
- Communications: emails and messages you send to support.
Cookies: we use only cookies that are necessary for sign-in and security. We currently use no advertising cookies.
3. Purposes and legal bases
- Providing the Service: creating and managing accounts, connecting platforms, computing your business economics, producing recommendations and executing actions you approve (contract).
- Security, fraud prevention and audit logging (legitimate interests; legal obligation).
- Support and service communications (contract; legitimate interests).
- Improving the Service using aggregated or de-identified data, without disclosing one merchant's confidential data to another (legitimate interests).
- Complying with law and lawful requests from authorities (legal obligation).
- Marketing messages to business contacts, only with consent, which you may withdraw at any time (consent).
4. Data from TikTok, Shopee and other platforms
- We access platform data only through official APIs and only with your authorization. We do not scrape private seller data.
- We use that data solely to provide CEONEQ to you. We do not sell it or share it with third parties, except service providers processing it on our behalf (section 5).
- When you instruct an action (for example, adjusting an ad budget), we send only the necessary request to that platform, subject to the approvals and guardrails you configure.
- You can disconnect at any time. On disconnection, access tokens are revoked immediately and data is deleted as described in section 7.
- We comply with each platform's developer terms and data policies. Where a platform requires a shorter retention period than this policy, we apply the shorter period.
6. International transfers
Some service providers may process data outside Thailand (for example in the United States, Singapore or the European Union). We transfer data only where the PDPA permits it, for example where the destination has adequate protection standards or appropriate contractual safeguards are in place.
7. Retention
- Account data: for as long as the account is active; deleted or de-identified within 30 days after account closure.
- Connected platform data (including original source evidence): up to 25 months while connected; deleted within 90 days after disconnection or a deletion request.
- Platform access tokens: revoked immediately on disconnection.
- Business data you provide and analysis results: for as long as the account is active; deleted with the account.
- Audit and security logs: 24 months.
- Support communications: 24 months.
- Backups: deleted as backup cycles roll over, within 35 days.
We keep data longer only where the law requires it or to establish, exercise or defend legal claims.
8. Security
We use appropriate measures, including encryption in transit (TLS), AES-256-GCM encryption of platform tokens, isolation of each organization's data at both the application and database level, role-based access control and audit logging. See our Security page for details.
No system is 100% secure. If a personal data breach occurs, we will notify Thailand's Personal Data Protection Committee within 72 hours where the law requires, and inform affected individuals without undue delay.
9. Your rights
Under the PDPA you have the right to:
- access your data and obtain a copy
- receive or transfer your data (portability)
- object to processing
- request erasure or destruction
- request restriction of use
- request correction
- withdraw consent (without affecting prior processing)
- lodge a complaint with the Personal Data Protection Committee
To exercise these rights, email privacy@ceoneq.com. We will verify your identity and respond within 30 days. Requests about buyer data held in a customer's store are forwarded to that customer, as the controller, and we assist on the customer's instructions.
10. Minors
The Service is for businesses and is not directed at persons under 20.
11. Changes
We may update this policy. We will announce material changes on the website or by email before they take effect.
12. Contact
IQX COMPANY LIMITED
Privacy: privacy@ceoneq.com · General support: support@ceoneq.com