Privacy Policy

Last updated: 14 April 2025

1. Introduction

MungKornSuccess Co., Ltd. ("Company", "we", "us") develops and operates Unified Platform, a Unified Chat Management Platform that connects to Facebook, Instagram, LINE OA, TikTok, Lazada, and Shopee.

This policy explains how we collect, use, disclose, and protect personal data when you use our services, including data received from Meta Platforms (Facebook and Instagram) via Facebook Login and the Meta Graph API.

2. Data We Collect

2.1 Data Received from Meta (Facebook / Instagram)

  • Facebook Page profile information for connected Pages (Page name, Page ID)
  • Customer messages and conversations sent to your Page
  • Names and profile pictures of users who message you (only as exposed by Facebook to Pages)
  • Page Access Tokens used to send reply messages on your behalf
  • Instagram Business Account information linked to your Page

2.2 Account Data

  • First name, last name, and email address used to register
  • Password (stored as a hashed value)
  • Organization membership information

2.3 Usage Data

  • System access logs (IP address, timestamp, browser)
  • Chat response statistics, response times, and in-app analytics

3. Purpose of Use

We use the collected data solely for the following purposes:

  • Providing the Unified Inbox — aggregating and displaying messages from all channels in one place so your team can respond efficiently.
  • Sending reply messages — sending messages on behalf of your Page via the Meta Graph API, as instructed by an Agent or Bot Rule.
  • Auto-reply Bot — processing messages to detect keywords and trigger automatic replies based on your configured rules.
  • Analytics and reporting — analysing conversation statistics to help you improve your service quality.
  • System security — monitoring and preventing abnormal or harmful usage.

4. Data Sharing with Third Parties

We do not sell, rent, or disclose your personal data to third parties for marketing purposes.

We may share data in the following limited cases:

  • Meta Platforms — sending reply messages via the Meta Graph API is governed by Meta's Privacy Policy.
  • Infrastructure providers — such as cloud hosting necessary for service delivery; these providers are restricted from using data for other purposes.
  • Legal requirements — when required by court order or a lawfully authorised authority.

4b. Data Received from Meta Platform

When you connect a Facebook Page or Instagram Business Account to Unified Platform via Meta Login, we store the following:

  • Page Access Tokens — stored with AES-256-GCM encryption; used solely to send reply messages on behalf of your Page.
  • Phone Number IDs (WhatsApp) — stored to identify your WhatsApp Business Channel; not used for any other purpose.
  • Message Metadata — timestamp, sender PSID, message ID displayed in the inbox; message content is not stored permanently beyond 90 days.
  • We do not store personal Facebook user data (e.g. email, phone, address) beyond what the Meta API explicitly exposes to Pages.

5. Data Retention

  • Page / WhatsApp Access Tokens — retained for the lifetime of the Channel and deleted immediately upon channel disconnection.
  • Messages and Message Metadata — retained for no more than 90 days after receipt.
  • Account data — retained for the lifetime of the active account.
  • After channel deletion — all associated data will be deleted within 30 days.
  • System logs — retained for no more than 90 days.

6. Data Security

We implement appropriate security measures, including:

  • TLS/HTTPS encryption for all data in transit
  • Passwords hashed with a secure algorithm (bcrypt)
  • Role-based access control per organisation
  • Webhook Signature verification to confirm data originates from Meta

7. Your Rights

You have the following rights regarding your personal data:

  • Right of Access — request to view personal data we hold about you.
  • Right to Rectification — request correction of inaccurate data.
  • Right to Erasure — request deletion of your personal data (see Section 8).
  • Right to Withdraw Consent — disconnect a Facebook Page at any time via the Channel Settings.
  • Right to Data Portability — request data in a machine-readable format.

To exercise these rights, please contact us at privacy@unified.in.th.

7b. Data Sharing with Meta Platforms

We do not sell your data to Meta or any party. Data exchanges with Meta occur solely to fulfil platform requirements:

  • Sending replies — Access Tokens are used to call the Meta Graph API to send messages on behalf of your Page as instructed by an Agent.
  • Webhooks — Meta sends Webhook Events to us; we do not send user data back to Meta beyond reply messages.
  • Data Deletion Callback — Meta may call POST /api/meta/data-deletion to request deletion of data belonging to Facebook users who revoke app access.

8. Data Deletion Request

You can request deletion of all your data by:

  • Via the platform — delete your account through Unified Platform Settings → Account → Delete Account.
  • Via Facebook Settings — go to Facebook Apps Settings and remove Unified Platform from your connected apps — Meta will automatically trigger our Data Deletion Callback.
  • Check request status — after submitting via Facebook you will receive a Confirmation Code. Check the status at /deletion-status.
  • Email request — send an email to privacy@unified.in.th with the subject "Data Deletion Request".

Upon receipt we will delete all your data — including messages, account, and associated data — within 30 days and confirm by email.

Deletion callback endpoint: POST /api/meta/data-deletion
Meta calls this endpoint automatically when a user revokes app permissions on Facebook.

9. Cookies and Tracking Technologies

We use cookies to manage login sessions and store user preferences. We do not use cookies to track behaviour across websites or for advertising.

10. Minors

Our services are not directed at persons under 13 years of age and we do not intentionally collect personal data from children under 13.

11. Changes to This Privacy Policy

We may update this policy from time to time. Material changes will be notified via email or in-app notification. The "Last updated" date at the top indicates when the policy was last revised.

12. Contact Us

If you have questions, concerns, or wish to exercise your rights regarding personal data, please contact us:

Company: MungKornSuccess Co., Ltd.

Email: privacy@unified.in.th

Website: https://unified.in.th