Legal & PoliciesPrivacy Policy

Privacy Policy

Last updated: April 12, 2026

011. Introduction and Scope

This Privacy Policy describes how Vito Marketplace ("Vito") collects, processes, stores, shares, and protects personal data in connection with the operation of its digital marketplace platform in the Kingdom of Thailand. This Policy applies to all Users of the Platform, including Buyers, Sellers, shop owners, and visitors. By using the Platform, you acknowledge and consent to the data practices described in this Policy. This Policy operates in full compliance with the Personal Data Protection Act B.E. 2562 (PDPA) of Thailand.

022. Data Controller

Vito acts as the data controller for personal data collected through the Platform. Vito determines the purposes and means of processing your personal data. For data protection inquiries, contact our data protection team at privacy@vito.com.

033. Categories of Personal Data Collected

  • Identity data: full name, username, profile photo.
  • Contact data: email address, phone number, messaging handle.
  • Account data: account type, registration date, verification status, account history.
  • Listing data: content, descriptions, photographs, pricing, and metadata of published listings.
  • Transaction data: purchase and sales history, payment method types (not full card numbers), order status.
  • Financial data: Vito Wallet balance and transaction history, platform fee records, subscription status.
  • Communication data: content of messages sent through the Platform's internal messaging system.
  • Usage data: pages visited, features used, search queries, click patterns, session duration.
  • Technical data: IP address, device type, browser type, operating system, cookies and tracking identifiers.
  • Geolocation data: approximate location, if permitted by the User's device settings.
  • Verification data: identification documents or business registration documents submitted for seller verification.

044. Legal Bases for Processing

  • Performance of contract: processing necessary to provide Platform services to you.
  • Legitimate interests: fraud detection, security, product improvement, and business analytics.
  • Legal obligation: compliance with Thai law, including PDPA, Anti-Money Laundering Act, and court orders.
  • Consent: marketing communications, geolocation tracking, and non-essential cookies — where applicable.

055. How We Use Your Data

  • To create, manage, and authenticate your account.
  • To facilitate and record Transactions between Users.
  • To process Platform Fee payments and manage your Vito Wallet.
  • To provide customer support and respond to complaints or disputes.
  • To enforce our Terms of Service, Community Rules, and other policies.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To improve the Platform through analytics and product development.
  • To send transactional notifications, policy updates, and (with consent) marketing communications.
  • To comply with applicable Thai law and respond to lawful authority requests.

066. Data Sharing and Disclosure

Vito does not sell your personal data to third parties for commercial purposes. We may share personal data in the following circumstances: (a) With other Users — only to the extent necessary for a Transaction (e.g., seller's public profile visible to buyers); (b) With service providers — trusted vendors processing data on Vito's behalf under data processing agreements (e.g., payment processors, cloud infrastructure, analytics); (c) With legal authorities — strictly in accordance with Thai law, court orders, or official government requests. Such disclosure is not guaranteed and depends on applicable legal requirements (see Section 9); (d) In the event of corporate restructuring — to a successor entity, subject to equivalent data protection obligations.

077. Data Retention

We retain personal data for as long as your account is active or as necessary to provide Platform services. After account deletion, we may retain certain data for up to five (5) years as required for: compliance with Thai legal obligations; resolution of disputes; fraud prevention; and audit and tax record-keeping purposes. Communication data may be retained for up to three (3) years for dispute resolution purposes.

088. Cookies and Tracking Technologies

We use essential cookies for platform operation (login sessions, preferences, security), analytical cookies (with your consent) to understand usage patterns, and optionally advertising cookies (with your consent) for relevant content. You may manage cookie preferences through your browser settings. Disabling essential cookies may impair Platform functionality.

099. Your Rights Under Thai PDPA

  • Right of access: request a copy of personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction: request temporary restriction of processing in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: withdraw previously given consent for any consent-based processing.
  • To exercise any of these rights, contact privacy@vito.com. We will respond within 30 days.

1010. Data Security

We implement industry-standard technical and organizational security measures, including TLS encryption for data in transit, encryption at rest for sensitive data, access controls and multi-factor authentication for system access, regular security audits and vulnerability assessments, and data breach response procedures in compliance with PDPA notification requirements. No system is completely secure. In the event of a data breach that poses a risk to your rights, we will notify you and the Office of the Personal Data Protection Committee (PDPC) as required by law.

1111. International Data Transfers

Certain service providers we engage may process your data outside of Thailand. In such cases, Vito ensures that appropriate safeguards are in place to protect your data in accordance with PDPA requirements, including contractual data protection obligations with third-party processors.

1212. Children's Privacy

The Platform is not directed at children and we do not knowingly collect personal data from individuals who are minors under Thai law. If you believe a minor has submitted personal data to the Platform, please contact privacy@vito.com and we will promptly delete such data.

1313. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via in-Platform notification or email. The current version is always available at vito.com/legal/privacy. Continued use of the Platform after the effective date of changes constitutes your acceptance.

1414. Contact and Complaints

For any data protection inquiry, right exercise request, or complaint, contact our Data Protection Officer at privacy@vito.com. You also have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) of Thailand.

Legal & Policies

Last updated: April 12, 2026