Legal
Privacy policy and PDPA rights
How information is used to provide services, maintain security and comply with law, including how to exercise your data rights.
Updated 9 September 2026
01Controller and contact
บริษัท ทุนทองมาวิน จำกัด, registration 0105555137558 (“Company” or “Money OK”), is the controller for activities whose purposes and means it determines. This covers the websites, enquiries, pawn services, sales of unredeemed items and branch communications.
Contact the Company about privacy or submit a rights request through the branch phones or addresses at the end of this page. Ask for the person responsible for personal-data matters. An ID copy or transaction document is not needed merely to ask for a contact channel.
02Information related to services
Information depends on the enquiry or transaction; not every category is collected from every visitor.
- Enquiries: name or account name, contact channel, messages, item type, model, condition and photos you provide, replies and coordination records.
- Branch transactions: identity, age, address, contact information, necessary evidence, item and appraisal details, pawn tickets, renewals, redemption, purchases, payments and related records.
- Complaints and rights requests: incident details, evidence, requests, identity or representative-authority checks and outcomes.
- Website use: IP address, device, browser, URLs, time and request data processed by hosting or security systems.
- Branch visits: video, audio, time and activity within CCTV coverage, as explained in the CCTV and audio notice.
Sources include you, authorised representatives, contact platforms, transaction and security records, and people or authorities lawfully involved in checks or complaints.
03Purposes and legal bases
Use is limited to relevant purposes and legal bases:
- Enquiries, preliminary appraisals and branch coordination: requested pre-contract steps or legitimate interests in customer service and follow-up.
- Identity and item-rights checks, transactions, documents and payments: contract performance and applicable legal duties.
- Required accounting, tax, ticket and register records and lawful official requests: legal obligations.
- Fraud prevention, protection of people and property, security, complaint investigation and establishing, exercising or defending claims: legitimate interests assessed for necessity and impact on your rights, or another genuinely applicable basis.
- Marketing or additional purposes requiring consent: separately requested before processing; visiting or receiving a service is not consent.
Business interests are not unlimited permission to use data. Security information is not automatically authorised for advertising.
04Required information and what not to send
Without information necessary for law, rights checks or a contract, we may be unable to appraise, verify identity, transact, address a request or provide that part of a service. Withholding unnecessary marketing data should not prevent the core service.
Initially, send only relevant item information. Avoid ID copies, account details, passwords, OTPs, payment-card details and unrelated people’s photos. Mask unnecessary religion, health or sensitive data unless its need and appropriate legal basis have been explained.
You must be authorised to provide another person’s information and inform them as appropriate. We may seek evidence or reject irrelevant, inaccurate or unlawful data. Information about minors, incapacitated people and sensitive categories is subject to specific legal conditions.
05Website and external services
Calculators and message tools process entries in your browser. There is no website pawn or instalment application backend. Chat messages are sent when you paste and send them yourself. A call link opens your phone app; the website does not place or record calls.
Hosting and content-delivery providers may process technical data to deliver and secure the service. Gold references are retrieved by the website server, without forwarding visitors’ IP addresses to the price source. The price provider receives the server’s request information. Embedded maps load on your request.
LINE, Messenger, Facebook, Instagram and maps operate their own systems and policies. This site does not install behavioural analytics tags or advertising pixels. Device storage is explained in the cookies policy.
06Website administrator accounts
Website administration is restricted to authorised accounts. An identity provider manages accounts, emails, passwords and sign-in. The website stores the administrator identifier, time and changed field names for access control and security review. This history is not public and is not a customer pawn-application database. Processing is limited to system administration, security and legal rights or duties, with access and retention-necessity reviews.
07Recipients and overseas processing
Disclosure is limited to what is necessary and lawful: responsible staff and branches; system, hosting, communications and security providers; relevant accountants, lawyers or insurers; competent authorities and courts; and people you lawfully authorise or request.
Communications, hosting or cloud services may involve overseas access or processing. Company transfers require an applicable legal basis and safeguards, such as adequate protection, appropriate safeguards or an applicable exception. A visit is not consent to unrestricted international transfers.
This policy does not authorise sale of personal data or publication of customer information without a lawful basis. Disclosure for claims or fraud prevention must be limited to the matter and responsible recipients.
08Retention
Retention is set and reviewed by category, not indefinitely for all data.
- Enquiries: while responding and following up and as necessary for service checks or related disputes; delete or de-identify once resolved and no longer needed.
- Tickets, transaction, accounting and tax records: during the relationship and applicable recordkeeping duties, limitation periods, checks or proceedings.
- Complaints, rights requests and evidence: through resolution and as necessary to demonstrate handling or establish, exercise or defend claims.
- Technical records: as needed for delivery, incidents and security, considering record type and system requirements.
- CCTV video and audio: at least 180 days from recording at every branch, subject to the CCTV notice.
When retention grounds end, delete, destroy or de-identify appropriately. Disputes, investigations, lawful orders or claims may require a hold on relevant records only, for as long as needed. Erasure requests do not automatically cancel statutory retention duties.
09Security
The Company must maintain organisational and technical measures appropriate to risk, limit access by role, control use and disclosure by purpose, and review measures as risks change. No system is represented as risk-free.
A data breach must be investigated and mitigated, with regulator or affected-person notification where required and within legal deadlines. Promptly report suspected impersonation or disclosure without further publishing other people’s data.
10PDPA rights and requests
Subject to legal conditions, you may request access or copies, the source of data collected without consent, correction, receipt or portability, objection, restriction, erasure, destruction or de-identification, and withdrawal where consent is the basis. Withdrawal does not affect lawful earlier processing.
Tell a branch which right you wish to exercise, your name, contact details and locating information such as transaction date or branch. For CCTV, give branch, date and approximate time. Proportionate identity or representative-authority checks may precede disclosure to prevent disclosure to the wrong person.
Requests are considered without delay and within legal deadlines. Lawful grounds, such as recordkeeping duties, claims or others’ rights, may prevent full compliance; reasons and handling must be provided and recorded as required. Verification must not unnecessarily delay rights.
You may complain to the Office of the Personal Data Protection Committee under law without waiving rights or requesting permission. Contacting us does not automatically suspend legal deadlines.
11Updates
Changes may reflect services, systems or law. An update date and appropriate notice of material changes will be provided. Consent for a new purpose will be sought beforehand where required; a policy edit does not replace consent or retrospectively change a legal basis.
บริษัท ทุนทองมาวิน จำกัด
Company registration 0105555137558
Contact the Company through a branch; ask for the person responsible for policies or personal data.
- Kilo Sun Junction Branch · Ubon Ratchathani
322/3 Sappasit Rd, Nai Mueang, Mueang Ubon Ratchathani, Ubon Ratchathani 34000
Call 081-966-8500 - Chayangkun Branch · Ubon Ratchathani
806/1 Chayangkun Rd, Nai Mueang, Mueang, Ubon Ratchathani 34000
Call 081-295-8500 - Nittayo Branch · Udon Thani
17 Moo 3, Nittayo Rd, Mak Khaeng, Mueang, Udon Thani 41000
Call 081-762-3500 - Sisaket Branch · Sisaket
1542/27-30 Si Sumang Rd, Mueang Tai, Mueang Sisaket, Sisaket 33000
Call 061-020-6600 - Ratchadamnoen Branch · Roi Et
99 Ratchakan Damnoen Rd, Nai Mueang, Mueang, Roi Et 45000
Call 081-778-0500
Questions about this policy?
Contact the branch that holds your contract, or message us on Facebook Messenger. We are happy to talk it through.