Privacy policy
Siam BC Co., Ltd. (บริษัท สยามบีซี จำกัด) Website: www.siambc.com
Effective Date: 31 August 2020 · Last Updated: 5 August 2026
Introduction
Siam BC Co., Ltd. (“the Company”, “we”, “us”, or “our”) places the highest importance on protecting the personal data of our customers, service users, website visitors, and anyone who contacts the Company.
This Privacy Policy explains how the Company collects, uses, discloses, transfers, stores, and protects your personal data, as well as your rights under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) and related laws.
This Policy applies to your use of the website www.siambc.com, purchases of products, use of our services, communications with the Company, and all contact through both online and offline channels.
Data Controller
Siam BC Co., Ltd. (บริษัท สยามบีซี จำกัด)
Company Registration Number: 0105563125121
Registered Address
110/2 Thawi Watthana-Kanchanaphisek 3 Rd Thawi Watthana Sub-district, Thawi Watthana District Bangkok 10170, Thailand
order@siambc.com · LINE @siambc
Telephone
082-554-6950 (+66 82 554 6950)
Definitions
Personal Data means any information relating to a natural person which enables the identification of that person, whether directly or indirectly.
Sensitive Personal Data means data as defined under Section 26 of the PDPA, such as racial or ethnic origin, religion, political opinions, health data, biometric data, criminal records, and other data prescribed by law.
Processing means the collection, use, disclosure, storage, recording, alteration, transfer, deletion, or any other operation performed on personal data.
Data Subject means the natural person to whom the personal data can be identified.
Data Controller means the person or entity having the authority to make decisions regarding the collection, use, or disclosure of personal data.
Data Processor means the person or entity who processes personal data pursuant to the instructions of the Data Controller.
Personal Data We Collect
The Company may collect the following data:
4.1 Identity Data
- First name
- Last name
- Gender (if provided)
- Date of birth (where necessary)
4.2 Contact Data
- Shipping address
- Billing address
- Telephone number
- Email address
- LINE ID
- Facebook Messenger
- Other contact channels
4.3 Account Data
- Username
- Password (stored in encrypted form)
- Login history
- Registration date
4.4 Order Data
- Product items
- Quantity
- Price
- Order number
- Parcel tracking number
- Purchase history
- Product warranty records
- Customer service contact history
4.5 Payment Data
The Company does not store full credit or debit card numbers.
Payments are processed through payment service providers that meet recognised security standards.
The Company may store only:
Payment status
Proof of transfer
Transaction reference number
4.6 Technical Data
- IP address
- Browser
- Operating system
- Device ID
- Cookies
- Session ID
- Log files
4.7 Website Usage Data
- Pages visited
- Duration of use
- Products of interest
- Search history
- Clicks
- Website interactions
4.8 Marketing Data
- Newsletter subscriptions
- Product interests
- Email open history
- Campaign responses
4.9 Corporate Customer Data (B2B)
- Contact person name
- Position
- Company
- Telephone number
- Email address
- Transaction-related information
Data We Do Not Collect
For the security of our customers, the Company does not collect, request, record, use, disclose, or process:
Seed Phrase
Recovery Phrase
Private Key
Passphrase
Hardware Wallet PIN
under any circumstances.
If any person claims to be an employee or representative of the Company and requests such information, please do not disclose it and notify the Company immediately.
Sensitive Personal Data
The Company does not ordinarily intend to collect sensitive personal data.
Where necessary, the Company will do so under an appropriate legal basis and will obtain explicit consent from the data subject where required by law.
Sources of Data
The Company obtains data from:
The data subject directly
The website
Contact forms
Membership registration
Product orders
Marketplaces such as Shopee, Lazada, and TikTok Shop
Payment service providers
Delivery companies
Technology service providers
Cookies and similar technologies
Purposes and Legal Bases
The Company processes personal data for the following purposes:
Purpose Legal Basis Receiving orders Performance of contract Delivering products Performance of contract Processing payments Performance of contract Product warranty Performance of contract After-sales service Performance of contract Fraud prevention Legitimate interests System security Legitimate interests Website analytics Legitimate interests and/or consent Sending newsletters Consent Compliance with tax and accounting laws Legal obligation
Where the Company relies on legitimate interests, we will balance our interests against the rights and freedoms of the data subject and will process only to the extent necessary.
Where the Company relies on consent, you may withdraw your consent at any time, without affecting processing already carried out prior to withdrawal.
If you do not provide necessary personal data, the Company may be unable to process your order, provide services, deliver products, or perform the contract.
Cookies
The website uses cookies to:
Ensure the website functions correctly
Improve usability
Analyse statistics
Remember user settings
Improve marketing
For non-essential cookies, the Company will request your consent before use. No non-essential cookies or scripts will be loaded until you have given consent.
You may change or withdraw your cookie consent at any time via the Cookie Banner or your web browser settings.
Details of each individual cookie, including its name, type, purpose, and retention period, are set out in the Company’s Cookie Policy at [insert Cookie Policy link].
Disclosure of Personal Data
The Company may disclose data to:
Payment service providers
Banks
Delivery companies
Marketplaces
Cloud service providers
Hosting providers
Website service providers
Email system providers
Marketing service providers
Data analytics providers
Cybersecurity providers
Auditors
Legal advisors
Government agencies
Regulatory authorities
The Company does not sell customers’ personal data to third parties for commercial purposes.
Data Processors
Our online store runs on an e-commerce platform provided by a third party, which acts as a data processor on our instructions and under a data processing agreement. Your account details, orders, delivery addresses and contact details are stored on e-commerce platform and cloud infrastructure located outside the Kingdom of Thailand.
The Company may engage Data Processors to act on its behalf, such as cloud hosting providers, website service providers, payment system providers, delivery service providers, marketing service providers, or information technology service providers. The Company will require such Data Processors to act in accordance with the Company’s instructions and to implement security measures for personal data as required by law, including entering into a Data Processing Agreement where appropriate.
Cross-Border Data Transfers
The Company may transfer data overseas through cloud service providers or information technology systems.
In such cases, the Company will comply with the PDPA and put in place appropriate safeguards, such as:
Standard Contractual Clauses (SCC)
Protective measures prescribed by law
The security standards of the service provider
to ensure that the data receives an adequate level of protection.
Data Retention Periods
Data Type Retention Period Member accounts For as long as the account remains active, and no longer than 5 years after account closure, unless otherwise required by law Orders At least 5 years, or as required by law Tax and accounting documents 5–10 years, as required by law Marketing data Until consent is withdrawn Computer traffic data (log files) At least 90 days, in accordance with the Computer Crime Act, or as required by law
Upon expiry of the retention period, the Company will delete, destroy, or anonymise the data.
Security Measures
The Company applies both technical and administrative security measures, such as:
SSL/TLS encryption
Access control
Password hashing
Firewall
Backup
Restriction of access rights
Log monitoring
System updates
Staff training
In the event of a personal data breach, the Company will act in accordance with the PDPA, including notifying the Office of the Personal Data Protection Committee within 72 hours where required by law, and notifying data subjects where the breach poses a high risk to their rights and freedoms.
Rights of Data Subjects
Data subjects have the following rights:
Right to be informed
Right of access
Right to obtain a copy of the data
Right to rectification
Right to erasure
Right to restrict processing
Right to object to processing
Right to withdraw consent
Right to data portability
Right to lodge a complaint with the Office of the Personal Data Protection Committee
The Company will respond to requests within 30 days of receipt, and may refuse a request where permitted by law, in which case the reasons will be communicated to the data subject.
Marketing
The Company will send news, promotions, and product information only where you have given consent, or where we may do so under a relevant legal basis.
You may unsubscribe from marketing communications at any time.
Minors
The website is not intended for minors.
If a data subject is under 20 years of age and has not attained legal majority, consent may need to be given by the person exercising parental authority as required by law.
If the Company becomes aware that data has been collected without valid consent, the Company will delete such data promptly.
Changes to This Policy
The Company may update this Policy from time to time.
Where changes are made, the Company will announce them on the website together with the effective date of the new version.
Contact
Siam BC Co., Ltd. (บริษัท สยามบีซี จำกัด)
110/2 Thawi Watthana-Kanchanaphisek 3 Rd, Thawi Watthana Sub-district, Thawi Watthana District, Bangkok 10170, Thailand
Email:
Telephone: 082-554-6950 (+66 82 554 6950)
You may contact the Company through the above channels to make enquiries, exercise your rights regarding personal data, or raise any data protection concerns.
Complaints
If you believe that the Company’s processing of your personal data does not comply with the law, you have the right to lodge a complaint with:
The Office of the Personal Data Protection Committee (PDPC)
Website: https://www.pdpc.or.th
Language of this policy
This policy is made in the Thai language. Where it is translated into another language and the versions conflict, the Thai version prevails.

