Last updated August 15, 2026
What personal data m1m collects, why we hold it, who we share it with, and the rights you have over it under Thai law.
m1m ("we", "us") is an online selling platform operated from Thailand. For the data described here we are the data controller, and you can reach us about it at hi@m1m.store.
This policy covers the platform itself. It does not cover what an individual merchant does with data you give them directly — see "Shops are responsible for their own customers" below.
Your account. The email address you register, your display name and avatar if you set one, your language preference, and — if you sign in with Discord — the account id and profile that Discord returns to us. We never receive your Discord password.
Sign-in. One-time codes we email you, held as a salted digest rather than in the clear, and the sessions those codes establish. A session is bound to one hostname, so signing in on the dashboard does not sign you in on a shop.
Selling. If you open a shop: its name and subdomain, your catalogue and its media, your orders and customers, your hosting credit balance and the top-ups behind it, and the payment account you nominate for receiving store credit.
Buying. The orders you place, the store credit you top up and spend at each shop, and the delivery record for anything sent to you.
Payments. When you top up by transfer we process the payment slip you upload and the reference the bank returns; when you top up by TrueMoney gift we process the gift link and its result. We see the account name and the masked account number a slip carries. We do not receive or store full card numbers or bank credentials.
Technical. Request logs, IP address, browser and device information, and error reports. These exist to keep the service running and to investigate abuse.
We use your data to run your account and sessions; to operate shops, catalogues, orders and delivery; to take payment and keep the credit ledgers accurate; to send service messages such as receipts and sign-in codes; to detect fraud and abuse; and to meet our legal and accounting obligations.
Our lawful bases are performance of the contract in our Terms of Service, our legitimate interest in keeping the platform secure and working, compliance with legal obligations, and consent where we ask for it. Where we rely on consent you can withdraw it at any time, without affecting what was done before.
We do not sell your personal data, and we do not use it to build advertising profiles.
When you buy from a shop on m1m, the merchant behind it receives what they need to fulfil your order — your account email, what you bought, and anything you send them about it. For that data, the merchant is the controller and we are their processor.
That means their own privacy notice governs how they use it, and a request to erase or correct it goes to them. We give merchants access strictly scoped to their own shop, enforced by the database rather than by the interface, and we require them by contract to handle it lawfully. But we cannot answer for how a given merchant does so.
We share data with service providers who process it on our instructions, and only as far as their job requires: our hosting and application platform, our database and authentication provider, our email delivery providers, our error-monitoring provider, our payment-slip verification provider, and Discord where you have connected it.
We may also disclose data where the law requires it, to enforce our terms, or to protect the rights and safety of our users — and to a buyer or successor if the business is sold, under the same protections stated here.
We use cookies that the service cannot work without: an authentication cookie that keeps you signed in, scoped to a single hostname, and a small cookie remembering your language choice. A shop never receives the dashboard's authentication cookie — it is stripped from the request before the shop's page is rendered.
We do not use advertising or cross-site tracking cookies.
Our providers operate globally, so your data may be processed outside Thailand. Where that happens we rely on the safeguards in our contracts with them, and on transferring only to providers offering an adequate standard of protection.
We keep account data while your account is open, and for a short period afterwards to handle disputes and closure. Order, payment and credit records are kept for as long as tax and accounting law requires, which is longer than an account may live. Sign-in codes expire in minutes. Technical logs are kept for a limited period and then discarded.
Some records survive deletion of an account on purpose. Store credit is money a merchant owes a shopper, so its ledger is deliberately protected from being erased by either side's account closure.
Under the Personal Data Protection Act you may ask us to give you a copy of your data or transfer it, correct it if it is wrong, erase it, restrict or object to how we use it, and withdraw a consent you gave.
Write to hi@m1m.store and we will answer within the time the law allows. We may need to confirm who you are first. Some rights have limits — we cannot erase a record we are legally required to keep — and where that applies we will tell you why. If you are not satisfied, you may complain to the Personal Data Protection Committee.
Access to your data is enforced in the database itself, so a request can only reach rows the signed-in identity is entitled to, rather than relying on the interface to hide them. Traffic is encrypted in transit, sign-in codes are stored as digests, uploaded media is private and served through short-lived signed links, and administrative access is limited to what operating the service requires.
No system is perfectly secure. If a breach affects your rights we will notify you and the regulator as the law requires.
m1m is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will remove it.
We may update this policy as the platform changes. The date at the top of this page is when the current version took effect, and we will announce material changes before they apply.
Privacy questions and rights requests go to hi@m1m.store. Anything else goes to hi@m1m.store.