ตั้งแต่วันที่ 24 กันยายน 2569 ผู้ควบคุมข้อมูลส่วนบุคคลของบริการ TouTop คือ บริษัท ท็อป ครีเอเตอร์ จำกัด (Top Creator Co., Ltd.) เลขประจำตัวผู้เสียภาษี 0105569182283 17/25 ซอยลาดพร้าว 23 แขวงจันทรเกษม เขตจตุจักร กรุงเทพมหานคร 10900 ข้อมูลที่ใช้รับชำระเงินและออกเอกสารภาษี เช่น สลิปเติมเงิน บัญชีรับเงิน และข้อมูลบนใบกำกับภาษี ใบเสร็จรับเงิน หรือหนังสือรับรองการหักภาษี ณ ที่จ่าย ยังประมวลผลโดย บริษัท คลาวด์ คอนเนคท์ เอเซีย จำกัด (Cloud Connect Asia Co., Ltd.) ในช่วงเปลี่ยนผ่าน เพื่อรับชำระเงินและปฏิบัติตามกฎหมายภาษี ใช้สิทธิตาม PDPA ได้ที่ admin@tuatop.com หัวข้อ PDPA Request
| หมวดข้อมูล | ตัวอย่าง | ใช้เพื่อ |
|---|---|---|
| บัญชีและโปรไฟล์ | ชื่อ, email, เบอร์โทร, รูปโปรไฟล์, บทบาท, bio, หมวดหมู่, พื้นที่ให้บริการ | สมัครสมาชิก, แสดงโปรไฟล์, ค้นหา creator/merchant |
| KYC/KYB และ Bookbank | เอกสารยืนยันตัวตน/ธุรกิจ, เลขผู้เสียภาษี, หน้าบัญชีธนาคาร, ชื่อบัญชี, ธนาคาร, เลขบัญชีบางส่วน | ยืนยันตัวตน, เปิดถอนเงิน, ตรวจบัญชีรับเงิน, ป้องกัน fraud |
| Wallet และธุรกรรม | ยอดเงิน, top-up slip, escrow, refund, withdrawal, ค่าบริการจัดการแคมเปญ, tax receipt, ledger, audit log | ชำระเงิน, คืนเงิน, ภาษี, บัญชี, ความปลอดภัย |
| งาน แชท และคอนเทนต์ | brief, proposal, deliverables, message, attachment, dispute evidence, moderation result | ดำเนินงาน, support, dispute, safety, AI assistant |
| ข้อมูลแพลตฟอร์มภายนอก | TikTok profile/stat ตามสิทธิ์ที่อนุญาต, Lazada order/product data เมื่อเชื่อม Commerce OS | ยืนยันช่องทาง, sync performance, affiliate/order tracking |
| อุปกรณ์และ log | IP address, user agent, session, event log, error log, terms acceptance record | ความปลอดภัย, audit, debugging, compliance |
| ความคิดเห็นและแบบสำรวจ | คำตอบแบบสำรวจในผลิตภัณฑ์ เช่น รู้จัก TouTop ครั้งแรกจากช่องทางไหน และเข้าใจว่า TouTop ทำอะไร (ตอบหรือไม่ตอบก็ได้) | วัดสุขภาพแบรนด์แบบรวม ปรับปรุงการสื่อสารและผลิตภัณฑ์ |
TouTop อาจใช้ AI เพื่อช่วยตอบ support เบื้องต้น สรุป context งาน ตรวจ Bookbank อ่านสลิป และตรวจข้อความ/โพสต์ที่เสี่ยงต่อคำหยาบ การคุกคาม เนื้อหาลามก หรือ spam หาก AI ตอบไม่ได้หรือเป็นเรื่องที่ต้องใช้ดุลยพินิจ ระบบจะส่งต่อให้แอดมิน
การตัดสินสำคัญ เช่น payout hold, dispute, refund, account suspension หรือ KYB/KYC rejection จะมี rule, log หรือ admin review ประกอบ ไม่อาศัย AI แบบไม่มีการตรวจสอบ
ปรับปรุงการเปิดเผยผู้รับข้อมูล Google: 8 ตุลาคม 2569
TouTop ใช้ YouTube API Services เมื่อคุณเลือก Connect YouTube และอนุญาตผ่าน Google เราขอสิทธิ์ youtube.readonly เพื่ออ่านข้อมูลช่องที่คุณอนุญาต รายการอัปโหลด และข้อมูลวิดีโอ โดยไม่ขอสิทธิ์อัปโหลด แก้ไข หรือลบวิดีโอบน YouTube การลงชื่อเข้าใช้ด้วย Google เป็นอีกขั้นตอนหนึ่งซึ่งอาจใช้ชื่อ รูปโปรไฟล์ และอีเมลเพื่อสร้างหรือระบุบัญชี TouTop ของคุณ
บริษัท ท็อป ครีเอเตอร์ จำกัด ผู้ดำเนินการ TouTop แชร์หรือส่งต่อข้อมูลจาก Google Sign-In และ YouTube API เฉพาะเท่าที่จำเป็นต่อฟีเจอร์ที่อธิบายในนโยบายนี้ ผู้รับข้อมูลและวัตถุประสงค์มีดังนี้:
เราไม่ขายข้อมูลผู้ใช้ Google และไม่แชร์ ส่งต่อ หรือเปิดเผยข้อมูลดังกล่าวให้เครือข่ายโฆษณาหรือนายหน้าข้อมูล เพื่อโฆษณาเฉพาะบุคคล การประเมินเครดิต/สินเชื่อ หรือการฝึกโมเดล AI/ML แบบทั่วไป การส่งต่อให้ผู้ให้บริการข้างต้นมีวัตถุประสงค์เพื่อให้บริการและดูแลฟีเจอร์ TouTop ที่ผู้ใช้ใช้งานเท่านั้น ไม่ใช่เพื่อวัตถุประสงค์อื่นที่ไม่เกี่ยวข้อง รายชื่อผู้ให้บริการทั่วไปในข้อ 5 ไม่ได้หมายความว่าผู้ให้บริการทุกรายได้รับข้อมูล Google ของคุณ ข้อ 4.2 และ 4.3 แยกอธิบายข้อมูลสำหรับ Analytics และ Push ซึ่งไม่ส่งข้อมูล YouTube API หรือ OAuth token
การใช้บริการ Google/YouTube อยู่ภายใต้ นโยบายความเป็นส่วนตัวของ Google โปรดติดต่อ admin@tuatop.com หากมีคำถามเกี่ยวกับข้อมูล YouTube ของคุณ
เมื่อเปิดระบบวัดผลและคุณยอมรับคุกกี้เพื่อการวิเคราะห์ TouTop จะส่งเหตุการณ์ที่กำหนดไว้ เช่น สมัครสมาชิก สร้างแคมเปญ สมัครงาน หรือลงทะเบียนอีเวนต์ ไปยัง Google Analytics ผ่านเซิร์ฟเวอร์ของเรา ข้อมูลจำกัดเฉพาะชื่อเหตุการณ์ หมวดหมู่ที่อนุญาต จำนวนหรือมูลค่าที่เกี่ยวข้อง และรหัสเซสชันแบบสุ่มของแท็บเบราว์เซอร์ โดยไม่ส่งชื่อ อีเมล รหัสบัญชี URL หน้าเว็บ คำค้นหา OAuth token เนื้อหาแชต หรือข้อมูลจาก YouTube API และไม่ใช้เหตุการณ์เหล่านี้เพื่อโฆษณาเฉพาะบุคคล
รหัสแท็บเก็บใน session storage และเปลี่ยนเมื่อมีการใช้งานครั้งถัดไปหลังหยุดใช้งานเกิน 30 นาที คุณถอนความยินยอมได้ที่การตั้งค่าคุกกี้ ระบบจะหยุดส่งเหตุการณ์ใหม่และลบรหัสในเครื่อง Google ประมวลผลข้อมูลที่ได้รับตามนโยบายความเป็นส่วนตัวและการตั้งค่าเก็บรักษาของ property ส่วนลิงก์ Google Calendar จะเปิดแบบร่างที่มีเฉพาะชื่องาน สถานที่ เวลา และลิงก์ TouTop สาธารณะ เพื่อให้คุณตรวจสอบและบันทึกเอง
เมื่อคุณเปิด Push บนอุปกรณ์ Google Firebase จะประมวลผลรหัส Firebase Installation ID การลงทะเบียน Push ของเบราว์เซอร์ และข้อมูลการนำส่ง TouTop เชื่อมรหัสดังกล่าวกับบัญชีที่เข้าสู่ระบบเพื่อส่งเพียงข้อความทั่วไปว่ามีการแจ้งเตือนใหม่ โดยไม่ส่งข้อความส่วนตัว รายละเอียดการเงิน เอกสารยืนยันตัวตน เนื้อหาแชต หรือข้อมูล YouTube ไปยัง Firebase Messaging คุณต้องเปิดแอปและเข้าสู่ระบบเพื่ออ่านรายละเอียด
คุณปิด Push ได้ในแผงแจ้งเตือนหรือการตั้งค่าเบราว์เซอร์ การปิดใน TouTop จะลบการลงทะเบียนนำส่งของอุปกรณ์ เมื่อออกจากระบบเบราว์เซอร์จะพยายามยกเลิกการลงทะเบียน หากออฟไลน์คุณปิดสิทธิ์ในเบราว์เซอร์ได้ ระบบลบรหัสอุปกรณ์ที่ไม่มีการใช้งาน 30 วันและข้อมูลคิวนำส่งที่เก่ากว่า 7 วัน Google ประมวลผลข้อมูลตามนโยบายของ Google การอนุญาต Push แยกจากคุกกี้วิเคราะห์และไม่เปิดการติดตามโฆษณา
เราใช้ผู้ให้บริการตามความจำเป็น เช่น Supabase สำหรับ database/storage/realtime, Vercel สำหรับ hosting, Resend หรือ provider email, LINE Login/Messaging API, banking/payment/slip verification provider เช่น KBank หรือ SlipOK เมื่อเปิดใช้งาน, Google Gemini หรือ AI provider สำหรับฟีเจอร์ AI, TikTok และ Lazada สำหรับการเชื่อมต่อที่ผู้ใช้อนุญาต
ผู้ให้บริการเหล่านี้อาจประมวลผลข้อมูลในสิงคโปร์ ไทย ญี่ปุ่น สหรัฐอเมริกา สหภาพยุโรป หรือ region อื่นตามระบบของผู้ให้บริการ เราใช้มาตรการสัญญาและความปลอดภัยที่เหมาะสมเมื่อจำเป็น
คุณมีสิทธิ์ขอเข้าถึง แก้ไข ลบ จำกัดการประมวลผล โอนย้ายข้อมูล คัดค้าน หรือถอนความยินยอมตาม PDPA โดยส่งคำขอที่ Profile หรือ email admin@tuatop.com หัวข้อ PDPA Request
ระบบใช้การยืนยันตัวตน, Row Level Security, audit log, server-side RPC, storage policy, encryption in transit และสิทธิ์ admin ที่จำกัดเท่าที่จำเป็น ธุรกรรมสำคัญ เช่น refund, payout, dormant maintenance fee และ admin action จะบันทึกประวัติไว้
คำถามเกี่ยวกับความเป็นส่วนตัว ส่งถึง admin@tuatop.com หรือดูช่องทางเพิ่มเติมที่ Contact
เมื่อ Creator สมัคร Event ระบบอาจนำข้อมูลจาก Profile และข้อมูล login มาเติมในฟอร์มให้อัตโนมัติ เช่น ชื่อ, email, เบอร์, จังหวัด, bio, social link, TikTok handle, LINE ID หรือข้อมูลจากการสมัคร Event ครั้งก่อน เพื่อให้ไม่ต้องกรอกซ้ำ. ช่องที่ยังไม่มีจะให้กรอกเพิ่มเฉพาะเท่าที่จำเป็น.
ผู้ใช้สามารถติดต่อ admin@tuatop.com เพื่อขอสอบถาม แก้ไข ลบ จำกัดการใช้ หรือใช้สิทธิ์ตามกฎหมายคุ้มครองข้อมูลส่วนบุคคลที่เกี่ยวข้อง.
Since 24 September 2026, the data controller for the TouTop service is บริษัท ท็อป ครีเอเตอร์ จำกัด (Top Creator Co., Ltd.), Tax ID 0105569182283, 17/25 Soi Lat Phrao 23, Chan Kasem, Chatuchak, Bangkok 10900, Thailand. Data needed to receive payments and issue tax documents, such as top-up slips, payout accounts and the details on tax invoices, receipts or withholding tax certificates, is still processed by บริษัท คลาวด์ คอนเนคท์ เอเซีย จำกัด (Cloud Connect Asia Co., Ltd.) during the transition to receive payments and meet tax law obligations. PDPA requests may be sent to admin@tuatop.com with subject PDPA Request.
| Category | Examples | Purpose |
|---|---|---|
| Account and profile | Name, email, phone, avatar, role, bio, category, service area | Registration, profile display, creator/merchant discovery |
| KYC/KYB and Bookbank | Identity/business documents, tax ID, bank account page, account name, bank, partial account number | Identity checks, payouts, payout account verification, fraud prevention |
| Wallet and transactions | Balance, top-up slip, escrow, refund, withdrawal, Campaign Management Service Fee, tax receipt, ledger, audit log | Payments, refunds, tax, accounting, security |
| Jobs, chat, and content | Briefs, proposals, deliverables, messages, attachments, dispute evidence, moderation results | Job workflow, support, disputes, safety, AI assistant |
| External platform data | TikTok profile/stats with permission, Lazada order/product data when Commerce OS is connected | Channel verification, performance sync, affiliate/order tracking |
| Device and logs | IP address, user agent, session, event log, error log, terms acceptance record | Security, audit, debugging, compliance |
| Survey and opinion data | Optional in-product survey answers, such as how you first heard about TouTop and what you understand it does | Aggregate brand-health reporting, improving our communication and product |
TouTop may use AI to answer initial support questions, summarize job context, review Bookbank images, read slips, and detect risky messages or posts such as profanity, harassment, sexual content, or spam. If AI cannot answer or the case requires judgment, it is escalated to admins.
Important decisions such as payout holds, disputes, refunds, account suspensions, or KYB/KYC rejection are supported by rules, logs, or admin review and are not made solely by unchecked AI.
Google data-sharing disclosure updated: 8 October 2026
TouTop uses YouTube API Services when you select Connect YouTube and authorize access through Google. We request youtube.readonly to read your authorized channel, uploads playlist, and video information. We do not request permission to upload, edit, or delete YouTube videos. Google sign-in is a separate flow that may use your name, profile image, and email to create or identify your TouTop account.
Top Creator Co., Ltd., the operator of TouTop, shares or transfers data obtained through Google Sign-In and the YouTube API only as necessary for the features described in this policy. The recipients and purposes are:
We do not sell Google user data or share, transfer or disclose it to advertising networks or data brokers, for personalized advertising, credit/lending decisions, or training generalized AI/ML models. Transfers to the service providers above are limited to providing and maintaining TouTop's user-facing features, not unrelated purposes. The general provider list in section 5 does not mean that every listed provider receives your Google user data. Sections 4.2 and 4.3 separately describe optional Analytics and Push data; those flows do not transmit YouTube API data or OAuth tokens.
Google/YouTube's processing is described in the Google Privacy Policy. Contact admin@tuatop.com with questions about your YouTube data.
When product analytics is enabled and you accept analytics cookies, TouTop sends selected interaction events (such as signing up, creating a campaign, applying for work, or registering for an event) to Google Analytics through our server. Data is limited to event names, permitted categories, relevant amounts or counts, and a random browser-tab session identifier. We do not include names, email addresses, account IDs, page URLs, search terms, OAuth tokens, chat content, or YouTube API data in these events. These events are not used for personalized advertising.
The tab identifier is stored in session storage and is replaced on the next interaction after 30 minutes of inactivity. You can withdraw consent through Cookie preferences; future events stop and the local identifier is removed. Google processes received analytics data under its privacy policy and the property's retention settings. Google Calendar links open a draft containing only the public event name, venue, time, and public TouTop link; you review and save it in Google Calendar yourself.
When you enable push notifications on a device, Google Firebase processes a Firebase Installation ID, browser push subscription and delivery information. TouTop links that installation to your signed-in account to send a generic notice when an in-app notification arrives. We do not send the notification's private text, payment details, identity documents, chat content or YouTube data to Firebase Messaging. Open the signed-in app to read details.
You can turn off push in the notification panel or browser settings. Turning it off in TouTop removes that device's delivery registration. On sign-out, the browser attempts to unregister its installation; if offline, revoke notifications in browser settings. Inactive device registrations are removed after 30 days; delivery queue records are removed after 7 days. Google processes delivery data under its privacy policy. Push is independent of optional analytics consent and does not enable advertising tracking.
We use service providers as needed, including Supabase for database/storage/realtime, Vercel for hosting, Resend or email providers, LINE Login/Messaging API, banking/payment/slip verification providers such as KBank or SlipOK when enabled, Google Gemini or AI providers for AI features, TikTok, and Lazada for user-authorized integrations.
These providers may process data in Singapore, Thailand, Japan, the United States, the European Union, or other relevant regions. We use appropriate contractual and security safeguards where required.
You may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent under PDPA through Profile or by emailing admin@tuatop.com with subject PDPA Request.
TouTop uses authentication, Row Level Security, audit logs, server-side RPCs, storage policies, encryption in transit, and limited admin permissions. Important actions such as refunds, payouts, dormant maintenance fees, and admin actions are logged.
Privacy questions may be sent to admin@tuatop.com. More support channels are listed at Contact.
When a creator registers for an event, TouTop may prefill the form from Profile and login data such as name, email, phone, province, bio, social link, TikTok handle, LINE ID, or previous event registration data. Missing fields are requested only when needed.
Users may contact admin@tuatop.com to ask questions or exercise rights to access, correct, delete, restrict, or otherwise manage personal data under applicable data protection law.