Hell Meat ("we") respects your privacy. This policy explains what we collect, why, who we share it with, and your rights under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
1. What we collect
- Order data — name, email, phone, LINE ID (optional), shipping address.
- Payment data — payment type and status (full card numbers are never stored — handled by Stripe, a PCI-DSS Level 1 certified processor).
- Site usage — IP, device, browser, pages visited, referrer / UTM parameters via Google Analytics 4 and PostHog.
- Cookies — cart, UTM attribution, language preference (details below).
- Newsletter signups — email and language when you opt in.
2. Purpose & legal basis
- Contract performance — fulfilling your order, shipping, receipts, order communication.
- Legitimate interest — fraud prevention, analytics for product improvement.
- Consent — marketing emails (only what you opt into).
- Legal obligation — sales records retention required by Thai tax & accounting law.
3. Sharing
We share data with vendors necessary to operate the business:
- Stripe — payment processing (USA / Ireland / Singapore)
- Shippop and partner carriers (Flash, Kerry, J&T, Thai Post) — fulfilling delivery
- Resend — transactional and newsletter email (USA)
- PostHog and Google Analytics — product analytics
- DigitalOcean — database and hosting (Singapore)
We do not sell your data. Cross-border transfers are subject to appropriate safeguards.
4. Cookies
hm_cart— your cart (HttpOnly, 30-day max age)hm_utm— first-touch attribution (HttpOnly, 30 days)_ga,ph_*— Google Analytics, PostHog
5. Retention
Order data: 7 years (Thai tax law). Newsletter subscriber data: until you unsubscribe. Analytics: up to 14 months.
6. Your PDPA rights
- Access the data we hold about you
- Correct inaccurate data
- Request deletion (subject to legal retention obligations)
- Data portability
- Withdraw marketing consent at any time
- Lodge a complaint with the Personal Data Protection Committee (PDPC)
Exercise these rights by emailing [email protected]
7. Security
Data in transit is TLS-encrypted. Stored credentials and tokens are hashed. No system is 100% secure and we cannot guarantee absolute safety.
8. Children
This service is not intended for users under 18. We do not knowingly collect data from minors.
9. Privacy contact
Questions about this policy or to exercise your rights: [email protected]