นโยบายความเป็นส่วนตัวPrivacy Policy

อัปเดตล่าสุด 30 กรกฎาคม 2026 · Last updated 30 July 2026

ภาษาไทย

Summy (เว็บไซต์ summydays.com) เป็นเครื่องมือรวมยอดขายและคำนวณกำไรสำหรับเจ้าของร้านค้าออนไลน์ เอกสารนี้อธิบายว่าเราเก็บข้อมูลอะไร เก็บไว้ที่ไหน ใช้ทำอะไร และคุณควบคุมข้อมูลของคุณได้อย่างไร โดยเขียนตามสิ่งที่ระบบทำจริง

1.เราคือใคร และเอกสารนี้ครอบคลุมอะไร

Summy ("เรา") ให้บริการผ่านเว็บไซต์ summydays.com ผู้ใช้บริการ ("คุณ") คือเจ้าของร้านค้าออนไลน์ และทีมงานที่เจ้าของร้านเชิญเข้ามาใช้งาน

เอกสารนี้ครอบคลุมทุกหน้าบนเว็บไซต์ summydays.com รวมถึงการเชื่อมต่อร้านค้าและบัญชีโฆษณาของคุณกับ TikTok Shop, Shopee, Lazada และ Meta

ติดต่อเรื่องข้อมูลส่วนบุคคล: support@summydays.com

2.ข้อมูลบัญชีผู้ใช้ที่เราเก็บ

  • อีเมลที่ใช้สมัคร และชื่อที่แสดง (ถ้าเข้าสู่ระบบด้วย Google เราได้รับเฉพาะอีเมลและชื่อจาก Google)
  • รหัสผ่าน — จัดการโดยระบบยืนยันตัวตนของ Supabase ในรูปแบบที่เข้ารหัสทางเดียว (hash) เราไม่เห็นและไม่เก็บรหัสผ่านจริงของคุณ
  • ชื่อร้าน โลโก้ และรูปโปรไฟล์ที่คุณอัปโหลดเอง
  • บทบาทและสิทธิ์การเข้าถึงเมนู (เจ้าของร้าน / ทีมงาน) รวมถึงคำเชิญที่ยังไม่ตอบรับ
  • คำตอบแบบสอบถามสั้นๆ ตอนเริ่มใช้งาน (เช่น ประเภทสินค้า ขนาดร้าน) ซึ่งคุณกรอกเองหรือกดข้ามได้
  • เรื่องที่คุณแจ้งเข้ามาผ่านระบบแจ้งปัญหา และบันทึกการทำงานของระบบ (log) ที่ใช้ตรวจหาสาเหตุเมื่อเกิดข้อผิดพลาด

3.ข้อมูลที่เราดึงจากแพลตฟอร์มร้านค้าของคุณ

เราดึงข้อมูลได้ต่อเมื่อคุณกดอนุญาตการเชื่อมต่อ (OAuth) ด้วยตัวเอง และดึงเฉพาะร้าน/บัญชีโฆษณาที่คุณเชื่อมไว้เท่านั้น รายการที่ระบบดึงและบันทึกไว้จริงมีดังนี้

  • คำสั่งซื้อ: เลขที่คำสั่งซื้อ วันเวลาที่สั่งซื้อและที่ชำระเงิน สถานะ รหัสสินค้า (SKU) ของผู้ขาย จำนวน ยอดขาย ส่วนลด/คูปอง และยอดคืนเงิน/ยกเลิก
  • รายการรับเงิน (settlement): ค่าธรรมเนียมแพลตฟอร์ม ค่าคอมมิชชั่น ค่าคอมมิชชั่นครีเอเตอร์/affiliate ค่าขนส่ง ยอดที่โอนเข้าบัญชีร้าน และรายการถอนเงิน
  • สินค้า: ชื่อสินค้า รหัสสินค้า บาร์โค้ด ราคาขาย และรูปสินค้า
  • ค่าโฆษณา: ยอดใช้จ่ายรายวัน รายแคมเปญ และรายสินค้า จาก TikTok Ads, Shopee Ads, Lazada Sponsored Solutions และ Meta Ads
  • ทราฟฟิกของร้าน: จำนวนการมองเห็น (impression) คลิก ผู้เข้าชม การเข้าหน้าสินค้า และยอดขายแยกตามช่องทางที่ขาย (ไลฟ์ / วิดีโอ / การ์ดสินค้า)
  • ข้อมูลร้าน: ชื่อร้าน รหัสร้านฝั่งแพลตฟอร์ม และชื่อ/ชื่อผู้ใช้ของครีเอเตอร์ที่ได้รับค่าคอมมิชชั่นจากร้านของคุณ
  • โทเคนการเชื่อมต่อ (access token / refresh token) ที่แพลตฟอร์มออกให้ เพื่อดึงข้อมูลรอบถัดไปได้โดยไม่ต้องให้คุณกดอนุญาตซ้ำทุกวัน
  • ข้อความแจ้งเตือน (webhook) ที่แพลตฟอร์มส่งมาเมื่อคำสั่งซื้อเปลี่ยนสถานะหรือสิทธิ์การเชื่อมต่อเปลี่ยน โดยเก็บข้อความต้นฉบับไว้เพื่อประมวลผลซ้ำได้หากระบบขัดข้องระหว่างทาง

เราไม่ขอสิทธิ์เกินกว่าที่จำเป็นต่อการทำรายงาน และไม่ใช้สิทธิ์ที่ได้ไปแก้ไขข้อมูลบนร้านของคุณ (ดูข้อกำหนดการใช้บริการ ข้อ 2)

4.ข้อมูลผู้ซื้อ — เราไม่เก็บ

ระบบไม่เก็บชื่อ-นามสกุล ที่อยู่จัดส่ง เบอร์โทรศัพท์ อีเมล หรือข้อมูลการชำระเงินของผู้ซื้อของคุณ

ตารางคำสั่งซื้อในฐานข้อมูลของเราไม่มีช่องสำหรับข้อมูลเหล่านั้นอยู่เลย ช่องเดียวที่เกี่ยวกับผู้ซื้อคือรหัสอ้างอิงนิรนามที่แพลตฟอร์มออกให้ (buyer_user_id) ซึ่งไม่ใช่ชื่อและไม่ใช่ข้อมูลติดต่อ และปัจจุบันทุกเส้นทางนำเข้าข้อมูลบันทึกช่องนี้เป็นค่าว่างทุกแถว

กรณีคำตอบจาก API ของแพลตฟอร์มมีข้อมูลผู้ซื้อแนบมาด้วย ระบบจะอ่านเฉพาะฟิลด์ที่เป็นตัวเลขทางการเงินและรหัสสินค้าเพื่อนำไปคำนวณ ส่วนที่เหลือถูกทิ้งไปโดยไม่บันทึกลงฐานข้อมูล

ผลคือเราไม่มีข้อมูลส่วนบุคคลของผู้ซื้อให้ค้นหา ส่งออก หรือเปิดเผยแก่ใคร ข้อยกเว้นเดียวคือข้อความ webhook ต้นฉบับที่แพลตฟอร์มส่งมา ซึ่งโดยปกติมีเพียงเลขที่คำสั่งซื้อ สถานะ และเวลา เก็บไว้เพื่อประมวลผลซ้ำเท่านั้น และเข้าถึงได้จากฝั่งเซิร์ฟเวอร์เท่านั้น

5.เราใช้ข้อมูลทำอะไร

  • แสดงรายงานยอดขาย กำไร ต้นทุน ค่าธรรมเนียม ค่าโฆษณา และกระแสเงินสด ให้คุณและทีมงานที่คุณให้สิทธิ์เท่านั้น
  • คำนวณต้นทุนสินค้า กำไรต่อคำสั่งซื้อและต่อสินค้า และภาษีมูลค่าเพิ่มโดยประมาณ
  • ซิงค์ข้อมูลให้เป็นปัจจุบันตามรอบเวลาที่ตั้งไว้ และเมื่อแพลตฟอร์มแจ้งการเปลี่ยนแปลงเข้ามา
  • แจ้งเตือนคุณเมื่อสิทธิ์การเชื่อมต่อร้านใกล้หมดอายุหรือถูกยกเลิก และตรวจแก้กรณีดึงข้อมูลไม่สำเร็จ

เราไม่ขาย ไม่ให้เช่า และไม่แลกเปลี่ยนข้อมูลของคุณกับบุคคลที่สาม ไม่ใช้ข้อมูลของคุณเพื่อยิงโฆษณา และไม่นำข้อมูลของร้านคุณไปแสดงหรือรวมเป็นสถิติให้ร้านอื่นเห็น

6.การแยกข้อมูลระหว่างร้าน และความปลอดภัย

  • ทุกแถวข้อมูลผูกกับรหัสร้าน (tenant) และบังคับด้วย Row-Level Security ของฐานข้อมูล PostgreSQL — บัญชีของคุณอ่านได้เฉพาะร้านที่คุณเป็นสมาชิก
  • ตารางที่เก็บโทเคนการเชื่อมต่อและข้อความ webhook ต้นฉบับ ถูกปิดไม่ให้เบราว์เซอร์เข้าถึงโดยตรง เข้าถึงได้จากฝั่งเซิร์ฟเวอร์เท่านั้น
  • การรับส่งข้อมูลทั้งหมดผ่าน HTTPS
  • ข้อความ webhook ทุกใบถูกตรวจลายเซ็นดิจิทัล (HMAC-SHA256) และเปรียบเทียบแบบ timing-safe ก่อนประมวลผล ใบที่ลายเซ็นไม่ตรงถูกปฏิเสธทันที
  • เจ้าของร้านกำหนดได้ว่าทีมงานคนไหนเห็นเมนูใด และพักการใช้งานบัญชีทีมงานได้ทุกเมื่อ

ไม่มีระบบใดปลอดภัย 100% หากเกิดเหตุข้อมูลรั่วไหลที่กระทบคุณ เราจะแจ้งให้คุณทราบทางอีเมลโดยไม่ชักช้า

7.เก็บข้อมูลไว้ที่ไหน และนานแค่ไหน

  • ฐานข้อมูล PostgreSQL และระบบยืนยันตัวตน: Supabase
  • เว็บไซต์ ฟังก์ชันประมวลผล และบันทึกการทำงานของระบบ: Vercel
  • เซิร์ฟเวอร์ของผู้ให้บริการทั้งสองรายอยู่ต่างประเทศ ข้อมูลของคุณจึงถูกเก็บและประมวลผลนอกประเทศไทย
  • ระยะเวลาเก็บ: เก็บไว้ตลอดเวลาที่คุณยังใช้บริการ เพราะรายงานย้อนหลังและการเปรียบเทียบช่วงเวลาต้องใช้ข้อมูลเดิม
  • เมื่อลบร้านหรือปิดบัญชี ข้อมูลของร้านนั้น (คำสั่งซื้อ ต้นทุน ค่าโฆษณา โทเคนการเชื่อมต่อ และรายชื่อทีมงาน) จะถูกลบตามไปด้วย
  • เมื่อคุณกดถอนการเชื่อมต่อร้าน โทเคนของร้านนั้นถูกลบทันที และระบบหยุดดึงข้อมูลใหม่จากแพลตฟอร์มนั้น

ถ้าต้องการให้ลบข้อมูลก่อนกำหนด แจ้งมาที่ support@summydays.com เราจะดำเนินการภายใน 30 วัน และยืนยันกลับทางอีเมล

8.บุคคลที่สามที่เกี่ยวข้อง

  • Supabase — ฐานข้อมูลและระบบยืนยันตัวตน (ทำหน้าที่ประมวลผลข้อมูลแทนเรา)
  • Vercel — โฮสต์เว็บไซต์และฟังก์ชันประมวลผล
  • TikTok Shop, Shopee, Lazada และ Meta — เฉพาะร้าน/บัญชีโฆษณาที่คุณกดเชื่อมเอง เราเรียก API ตามขอบเขตสิทธิ์ที่คุณอนุญาต และปฏิบัติตามข้อกำหนดของแต่ละแพลตฟอร์ม
  • Google — เฉพาะกรณีที่คุณเลือกเข้าสู่ระบบด้วยบัญชี Google
  • ผู้ให้บริการโมเดลภาษา (Anthropic โดยตรง หรือผ่าน Vercel AI Gateway) — ทำงานเฉพาะเมื่อคุณกดปุ่มวิเคราะห์ด้วย AI เอง และส่งไปเฉพาะผลสรุปตัวเลขของหน้าที่คุณเปิดอยู่ ไม่ส่งรายการคำสั่งซื้อดิบ ฟีเจอร์นี้ปิดอยู่จนกว่าร้านของคุณจะเปิดใช้งาน

เว็บไซต์ของเราไม่มีสคริปต์ติดตามโฆษณาหรือเครื่องมือวิเคราะห์พฤติกรรมของบุคคลที่สาม

เราอาจต้องเปิดเผยข้อมูลเมื่อกฎหมายบังคับหรือมีคำสั่งจากหน่วยงานที่มีอำนาจ โดยจะเปิดเผยเท่าที่กฎหมายกำหนดเท่านั้น

9.คุกกี้และข้อมูลที่เก็บในเบราว์เซอร์

  • คุกกี้ที่จำเป็นสำหรับการเข้าสู่ระบบ (ออกโดยระบบยืนยันตัวตนของ Supabase) — ไม่มีคุกกี้นี้จะเข้าสู่ระบบไม่ได้
  • ค่าการแสดงผล เช่น ธีมสี ภาษา และรูปแบบการ์ด เก็บไว้ใน localStorage ของเบราว์เซอร์คุณเอง ไม่ได้ใช้ระบุตัวบุคคล

เราไม่ใช้คุกกี้โฆษณา และไม่มีการติดตามพฤติกรรมข้ามเว็บไซต์

10.สิทธิ์ของคุณ

  • ขอดูหรือขอสำเนาข้อมูลที่เรามีเกี่ยวกับคุณ
  • ขอแก้ไขข้อมูลที่ไม่ถูกต้อง
  • ขอลบข้อมูลหรือลบบัญชี
  • ถอนความยินยอมการเชื่อมต่อร้านได้เองทุกเมื่อ ที่หน้าเชื่อมต่อร้าน (/connect/tiktok, /connect/shopee, /connect/lazada, /connect/meta) โดยกดถอนการเชื่อมต่อในแถวของร้านนั้น
  • คัดค้านหรือขอให้จำกัดการประมวลผล และร้องเรียนต่อหน่วยงานคุ้มครองข้อมูลส่วนบุคคล

ส่งคำขอมาที่ support@summydays.com เราจะตอบกลับภายใน 30 วัน และอาจขอให้ยืนยันตัวตนก่อนดำเนินการเพื่อความปลอดภัยของบัญชีคุณ

11.ผู้ใช้ที่เป็นเยาวชน

บริการนี้สำหรับผู้ประกอบการ ไม่ได้มุ่งให้บริการผู้ที่มีอายุต่ำกว่า 18 ปี และเราไม่มีเจตนาเก็บข้อมูลของเยาวชน หากพบว่ามีการเก็บโดยไม่ได้ตั้งใจ เราจะลบให้เมื่อได้รับแจ้ง

12.การเปลี่ยนแปลงนโยบายนี้

หากมีการแก้ไข เราจะเปลี่ยนวันที่อัปเดตล่าสุดที่ด้านบนของหน้านี้ และหากเป็นการเปลี่ยนแปลงที่กระทบสิทธิ์ของคุณอย่างมีนัยสำคัญ เราจะแจ้งให้ทราบในแอปหรือทางอีเมลก่อนมีผลบังคับใช้


English

Summy (summydays.com) is a reporting tool that consolidates sales and calculates true profit for online sellers. This policy explains what we collect, where it is stored, what we use it for, and how you stay in control. It describes what the product actually does, not a generic template.

1.Who we are and what this policy covers

Summy ("we") operates the website summydays.com. Our users ("you") are online shop owners and the team members they invite.

This policy covers every page on summydays.com, including connecting your shops and ad accounts on TikTok Shop, Shopee, Lazada and Meta.

Privacy contact: support@summydays.com

2.Account data we collect

  • The email address you sign up with and your display name (if you sign in with Google, we receive only your email address and name from Google).
  • Your password, handled by Supabase Auth as a one-way hash. We never see or store your actual password.
  • Shop name, logo and profile picture that you upload yourself.
  • Role and per-menu access permissions (owner / staff), including pending invitations.
  • Short onboarding answers (for example product category and shop size) that you fill in yourself or skip.
  • Support tickets you submit and system logs used to diagnose errors.

3.Data we pull from your marketplace platforms

We can only pull data after you personally authorise the connection (OAuth), and only for the shops and ad accounts you connected. What we actually pull and store:

  • Orders: order number, order and payment timestamps, status, seller SKU, quantity, revenue, discounts and vouchers, refunds and cancellations.
  • Settlements: platform fees, commission, creator/affiliate commission, shipping charges, amounts paid out to the shop, and withdrawals.
  • Products: product name, SKU, barcode, selling price and product image.
  • Ad spend: daily, per-campaign and per-product spend from TikTok Ads, Shopee Ads, Lazada Sponsored Solutions and Meta Ads.
  • Shop traffic: impressions, clicks, visitors, product page views, and GMV split by sales surface (live / video / product card).
  • Shop information: shop name, platform-side shop id, and the name or handle of creators who earned commission from your shop.
  • Connection tokens (access and refresh tokens) issued by the platform, so the next sync can run without asking you to re-authorise every day.
  • Push notifications (webhooks) sent by the platform when an order status or an authorisation changes. We keep the original message so it can be reprocessed if something fails mid-way.

We do not request scopes beyond what the reports need, and we do not use the granted access to modify anything in your shop (see Terms of Service, section 2).

4.Buyer data — we do not store it

We do not store your buyers' names, shipping addresses, phone numbers, email addresses or payment details.

Our orders table has no columns for any of that. The only buyer-related column is the platform's opaque buyer reference (buyer_user_id), which is not a name and not contact information — and today every import path writes that column as empty (null) on every row.

When a platform API response happens to include buyer details, we read only the financial figures and product identifiers we need for the calculation, and the rest is discarded without ever being written to the database.

As a result we have no buyer personal data to search, export or disclose to anyone. The only exception is the original webhook message sent by the platform — typically just an order number, a status and a timestamp — kept for reprocessing and readable from our server only.

5.How we use the data

  • Show reports on sales, profit, cost, fees, ad spend and cash flow to you and the team members you authorise, and to nobody else.
  • Calculate product cost, profit per order and per product, and estimated VAT.
  • Keep your data current on the scheduled sync and when the platform pushes a change.
  • Alert you when a shop authorisation is about to expire or has been revoked, and troubleshoot failed syncs.

We do not sell, rent or trade your data with third parties. We do not use your data for advertising, and we never show or aggregate your shop's data for another shop to see.

6.Isolation between shops, and security

  • Every row is bound to a tenant id and enforced by PostgreSQL Row-Level Security — your account can only read the shops you are a member of.
  • The tables holding connection tokens and raw webhook messages are closed to the browser entirely and reachable only from our server.
  • All traffic runs over HTTPS.
  • Every webhook is verified with an HMAC-SHA256 signature using a timing-safe comparison before it is processed; messages with an invalid signature are rejected.
  • Shop owners control which menus each team member can see, and can suspend a team member's access at any time.

No system is perfectly secure. If a breach affects you, we will notify you by email without undue delay.

7.Where data is stored, and for how long

  • PostgreSQL database and authentication: Supabase.
  • Website, serverless functions and system logs: Vercel.
  • Both providers host outside Thailand, so your data is stored and processed outside Thailand.
  • Retention: we keep your data for as long as you use the service, because historical reports and period-over-period comparisons depend on it.
  • When a shop or an account is deleted, that shop's data (orders, costs, ad spend, connection tokens and team membership) is deleted with it.
  • When you disconnect a shop, its tokens are deleted immediately and we stop pulling new data from that platform.

To have your data deleted sooner, email support@summydays.com. We will complete the deletion within 30 days and confirm by email.

8.Third parties involved

  • Supabase — database and authentication (acting as a processor on our behalf).
  • Vercel — website and serverless function hosting.
  • TikTok Shop, Shopee, Lazada and Meta — only the shops and ad accounts you connect yourself. We call their APIs within the scopes you granted and follow each platform's terms.
  • Google — only if you choose to sign in with a Google account.
  • Language model providers (Anthropic directly, or via Vercel AI Gateway) — used only when you press the AI analysis button yourself, and we send only the aggregated figures of the page you are viewing, never raw order rows. The feature stays off until your shop enables it.

Our site carries no third-party advertising trackers and no third-party behavioural analytics scripts.

We may have to disclose data where the law requires it or a competent authority orders it, and then only to the extent required.

9.Cookies and browser storage

  • Essential sign-in cookies issued by Supabase Auth — without them you cannot log in.
  • Display preferences such as theme, language and card style are kept in your own browser's localStorage and are not used to identify you.

We use no advertising cookies and do no cross-site tracking.

10.Your rights

  • Access or request a copy of the data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data or your account.
  • Withdraw a shop connection at any time yourself, on the connect pages (/connect/tiktok, /connect/shopee, /connect/lazada, /connect/meta), using the disconnect action on that shop's row.
  • Object to or restrict processing, and lodge a complaint with your data protection authority.

Send requests to support@summydays.com. We respond within 30 days and may ask you to verify your identity first, to protect your account.

11.Minors

This service is built for business operators and is not directed at anyone under 18. We do not intend to collect data about minors, and will delete such data if we are notified of it.

12.Changes to this policy

If we change this policy we will update the date at the top of this page, and for changes that materially affect your rights we will notify you in the app or by email before they take effect.