Privacy Policy
This English translation is provided for convenience. If there is any inconsistency, the Thai version prevails. อ่านฉบับภาษาไทย
Effective from [date] · Last updated 3 October B.E. 2569 (2026)
MoonUp System is operated by [legal entity name/service provider name] ("we") and is a point-of-sale (POS) and entertainment system for venues. This policy explains how we collect, use and disclose personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA).
1. Who is the data controller
- Venue and staff data (venue accounts, settings) — we are the data controller.
- In-venue sales data (bills, sales items, staff commissions, stock) — the venue is the data controller, and we are the data processor acting on the venue's behalf.
- Data of customers who use the entertainment pages (song requests, tips, warps, table bookings, concert tickets, coins) — we and the venue you use are each a data controller for our respective part.
2. Data we collect
Venues and staff
- Venue name, owner name, email, phone number, password (stored using one-way encryption) and staff PINs (stored encrypted).
- The PromptPay account the venue uses to receive payments, and the slip verification service key (stored encrypted).
- Information about the devices used, login history and sales data.
Customers who use the entertainment pages
- Data from signing in with LINE or Apple: the user ID from that provider, display name, profile picture and email (if the provider sends it).
- Service usage history: songs requested, tips, coin balance and coin transaction history, bookings and admission tickets.
- Payment data: amount, time and the bank transfer slip image, which may include the payer's name and a partial account number (we do not store bank passwords or card data).
- Content you submit yourself: warp photos, messages, social media account names you enter, comments and likes.
- Technical data: IP address, device/browser type and system usage logs.
3. What we use data for, and the legal basis
- Providing the service under contract — opening venue accounts, processing sales, song queues, table bookings, issuing tickets, managing coins and receiving payments.
- Verifying payments and preventing fraud (legitimate interest) — detecting duplicate slips, rate-limiting system calls, and checking for unusual transactions.
- Displaying warps on venue screens and the venue's web page (consent) — you tick to give consent every time you submit a warp, and you can delete it at any time.
- Complying with the law — retaining accounting and tax records, and responding to government authorities as required by law.
- Contacting venues — email verification, system issue notices and renewal notices.
We do not sell personal data, and we do not use customer data for third-party advertising.
4. Who sees your data
- The venue you use — sees your display name, the transactions you make at that venue, and the slips it needs to check. One venue cannot see your data at other venues.
- Other users at the venue — see warps, comments, display names and rankings, as you choose to disclose them (for example, social media hidden until unlocked).
- Service providers we use — LINE / Apple (sign-in), Slip2Go (slip verification), server and email providers [specify names], under confidentiality agreements.
- Government authorities — when required by law or by court order.
5. How long we keep data
- Sales and payment data — for the life of the venue account, and for at least [5] years under accounting/tax law.
- Slip images — [180 days] after the transaction is completed, unless there is a dispute.
- Warp photos and comments — until you, the venue or we delete them (warp is our service; the venue reviews photos on our behalf) · Takedown requests are retained for review as required by law.
- Customer accounts — until you delete your account (you can delete it yourself on the "Me" page). Once deleted, your remaining coins at all venues will be lost, and history that the law requires us to keep will be retained in de-identified form to the extent possible.
6. Your rights
You have the right to request access, request a copy, rectification, erasure, restriction of use, to object, to request data portability, and to withdraw consent, by contacting us as set out in section 8. We will respond within 30 days, and you have the right to lodge a complaint with the Office of the Personal Data Protection Committee.
7. Security and user age
We encrypt data in transit (HTTPS), encrypt important stored data, and restrict access rights according to staff duties. The entertainment pages are intended for persons aged 20 years or over. We do not intentionally collect data from minors.
8. Cookies and similar technologies
Cookies are small text files that a website stores in your browser. This website (moonupsystem.com and the customer pages at moonup.co) divides cookies and data stored in the browser into 3 categories.
- Necessary (always on, no consent required) — Cloudflare security cookies that protect against attacks and bots, Cloudflare Turnstile on the sign-up page, remembering your cookie choices, and sign-in (back office/customer pages), which are necessary to provide the service.
- Analytics (consent required) — counting visitors and pages used in aggregate, to improve the website.
- Marketing (consent required) — measuring and showing relevant advertising, such as the Facebook Pixel. Not currently in use. If we start using it, it will only run if you consent.
You can accept, reject or set preferences by category from the banner shown on your first visit, and you can change your mind or withdraw consent at any time via the Cookie settings link at the bottom of every page. Rejecting does not affect the main use of the website. You can also delete or block cookies in your browser settings.
9. Contact us
[Legal entity name] · [Address] · Email [privacy@…] · Tel. [phone number]
We may update this policy and will announce it on this page together with the date of update. If there is a material change, we will notify you through the system before it takes effect.