⬡ Cosmixon Hub
PayRadar

นโยบายความเป็นส่วนตัว

Privacy Policy

บริการยืนยันเงินเข้าอัตโนมัติสำหรับร้านค้า

Automatic money-in confirmation service for merchants

อัปเดตล่าสุด: 20 มิถุนายน 2026 Last updated: 20 June 2026

สารบัญContents

PayRadar (“เรา”) ให้ความสำคัญสูงสุดกับความเป็นส่วนตัวของคุณ. PayRadar คือบริการยืนยันเงินเข้าอัตโนมัติ: แอป Android บนมือถือของร้านค้าจะ “ฟังการแจ้งเตือน (notification)” จากแอปธนาคารเพื่อตรวจจับยอดเงินเข้า แล้วจับคู่กับบิลของร้านโดยอัตโนมัติ. นโยบายนี้อธิบายว่าเราเก็บข้อมูลอะไร ใช้ทำอะไร และคุณมีสิทธิ์อย่างไร โดยสอดคล้องกับ พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล (PDPA) และนโยบายของ Google Play.

PayRadar (“we”, “us”) takes your privacy seriously. PayRadar is an automatic money-in confirmation service: an Android app on the merchant’s phone “listens to the notifications” shown by banking apps to detect incoming payments, then automatically matches them to the merchant’s bills. This policy explains what we collect, how we use it, and your rights — in line with Thailand’s Personal Data Protection Act (PDPA) and Google Play policies.

1. ข้อมูลที่เราเก็บ1. What we collect

เราเก็บเฉพาะข้อมูลที่จำเป็นต่อการยืนยันการชำระเงินเท่านั้น:

  • เก็บข้อความการแจ้งเตือน (notification) จากแอปธนาคาร บนมือถือที่ติดตั้ง PayRadar — เพื่อดึงเฉพาะ ยอดเงินเข้า + เวลา + ชื่อแอปต้นทาง (เช่น SCB EASY, K PLUS) เท่านั้น
  • เก็บอีเมลและรหัสผ่าน ของบัญชีร้านค้า (merchant) — รหัสผ่านถูกเข้ารหัสแบบทางเดียว (hashed) ไม่เก็บเป็นข้อความจริง
  • เก็บหมายเลข PromptPay ของร้าน เพื่อสร้าง QR รับเงินที่ยอดถูกล็อก
  • เก็บสลิปที่ลูกค้าอัปโหลด (รูปภาพ) — ใช้เป็นช่องทางสำรอง (fallback) เมื่อระบบฟังการแจ้งเตือนไม่สามารถยืนยันได้
  • เก็บข้อมูลการใช้งานพื้นฐาน เช่น จำนวนการยืนยันต่อเดือน, อุปกรณ์ที่ผูกไว้, เวลาที่ออนไลน์ล่าสุด (เพื่อแสดงสถานะและคิดแพ็กเกจ)

We collect only what is necessary to confirm payments:

  • collectNotification text from banking apps on the phone where PayRadar is installed — solely to extract the money-in amount + time + source app name (e.g. SCB EASY, K PLUS).
  • collectMerchant account email and password — the password is stored only as a one-way hash, never in plain text.
  • collectPromptPay number of the shop, to generate amount-locked payment QR codes.
  • collectCustomer-uploaded slips (images) — used as a fallback when notification listening cannot confirm a payment.
  • collectBasic usage data such as confirmations per month, paired devices, and last-seen time (to show status and apply your plan).

2. ข้อมูลที่เราไม่เก็บ2. What we do NOT collect

  • ไม่เก็บเลขบัญชีธนาคารเต็ม
  • ไม่เก็บรหัส PIN / รหัสผ่านธนาคาร ของคุณ
  • ไม่เก็บเนื้อหาการแจ้งเตือนที่ไม่เกี่ยวกับการเงิน (แชต, ข่าว, โซเชียล ฯลฯ) — เราอ่านเฉพาะการแจ้งเตือนเงินเข้าจากแอปธนาคารที่รองรับเท่านั้น
สำคัญ: PayRadar ไม่ได้เข้าถึงแอปธนาคารของคุณโดยตรง และไม่ได้เชื่อมต่อกับบัญชีธนาคารของคุณ. เราอ่านเฉพาะ “ข้อความการแจ้งเตือน” ที่ปรากฏบนหน้าจอมือถือเท่านั้น เช่นเดียวกับที่คุณเห็นเอง.
  • neverFull bank account numbers
  • neverBanking PINs or passwords
  • neverNon-financial notification content (chats, news, social, etc.) — we read only money-in notifications from supported banking apps.
Important: PayRadar does not access your banking apps directly and is not connected to your bank account. It only reads the “notifications” shown on the device screen — the same ones you see yourself.

3. วัตถุประสงค์การใช้ข้อมูล3. How we use your data

เราใช้ข้อมูลข้างต้นเพื่อ จับคู่และยืนยันการชำระเงินให้กับร้านค้าเท่านั้น โดยเทียบยอดเงินเข้า (รวมเศษสตางค์เฉพาะ) กับบิลที่ร้านสร้างไว้.

เรา ไม่ ขาย ไม่ ให้เช่า และ ไม่ แชร์ ข้อมูลของคุณกับบุคคลที่สาม เพื่อการตลาดหรือวัตถุประสงค์อื่นใด. ข้อมูลถูกใช้ภายในเพื่อให้บริการ PayRadar เท่านั้น.

We use the data above only to match and confirm payments for merchants, by comparing incoming amounts (including the unique satang) against bills the merchant created.

We do NOT sell, rent, or share your data with third parties for marketing or any other purpose. Data is used internally only to operate the PayRadar service.

4. สิทธิ์อ่านการแจ้งเตือน (Notification Access)4. Notification access

PayRadar ใช้สิทธิ์ NotificationListener ของ Android เพื่ออ่านการแจ้งเตือนเงินเข้า. สิทธิ์นี้:

  • ปิดอยู่โดยค่าเริ่มต้น (default OFF) — จะไม่ทำงานจนกว่าคุณจะอนุญาตด้วยตนเอง
  • ก่อนเปิด แอปจะแสดง คำขอความยินยอม (consent) ที่ชัดเจน อธิบายว่าจะอ่านอะไรและเพื่ออะไร
  • คุณสามารถ ปิดหรือถอนสิทธิ์ได้ตลอดเวลา ที่ การตั้งค่า Android → การเข้าถึงการแจ้งเตือน หรือเพียง ถอนการติดตั้งแอป

หมายเหตุ: PayRadar รองรับเฉพาะ Android เท่านั้น เพราะ iOS ไม่อนุญาตให้แอปอ่านการแจ้งเตือนของแอปอื่น.

PayRadar uses Android’s NotificationListener permission to read money-in notifications. This permission:

  • Is OFF by default — it does nothing until you enable it yourself.
  • Requires explicit consent beforehand: the app clearly explains what it reads and why.
  • Can be revoked anytime via Android Settings → Notification access, or simply by uninstalling the app.

Note: PayRadar is Android-only, because iOS does not let apps read other apps’ notifications.

5. Dev API & Webhook5. Dev API & Webhook

ร้านค้า/นักพัฒนาสามารถรับเงินผ่าน PayRadar ด้วย API (ใช้คีย์ X-Api-Key) และตั้งค่า webhook URL ของตนเอง เพื่อรับเหตุการณ์การชำระเงิน. เมื่อจ่ายสำเร็จ PayRadar จะส่งคำขอไปยัง webhook ของคุณ (เช่น {event:"payment.paid", token, ref, amount}) พร้อมลายเซ็น HMAC-SHA256 เพื่อให้ตรวจสอบความถูกต้องได้.

webhook URL ที่คุณตั้งจะถูกเก็บไว้กับบัญชีของคุณและใช้เพื่อส่งการแจ้งเตือนการชำระเงินเท่านั้น. เราไม่ส่งข้อมูลส่วนบุคคลของลูกค้าผู้ชำระเงินไปยัง webhook.

Merchants/developers can accept payments via the PayRadar API (using an X-Api-Key) and configure their own webhook URL to receive payment events. On a successful payment, PayRadar sends a request to your webhook (e.g. {event:"payment.paid", token, ref, amount}) signed with an HMAC-SHA256 signature for verification.

The webhook URL you provide is stored with your account and used only to deliver payment notifications. We do not send paying customers’ personal data to your webhook.

6. สิทธิ์ของคุณ (PDPA)6. Your rights (PDPA)

ภายใต้ พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล (PDPA) คุณมีสิทธิ์:

  • เข้าถึง — ขอดูข้อมูลส่วนบุคคลที่เราเก็บเกี่ยวกับคุณ
  • แก้ไข — ขอแก้ไขข้อมูลที่ไม่ถูกต้องหรือไม่เป็นปัจจุบัน
  • ลบ — ขอลบบัญชีและข้อมูลทั้งหมดของคุณ ผ่านเมนู “ลบบัญชี” ในแอป หรือติดต่อทีมสนับสนุน
  • ถอนความยินยอม — ปิดสิทธิ์อ่านการแจ้งเตือน หรือหยุดใช้บริการได้ทุกเมื่อ

Under Thailand’s PDPA, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or outdated data.
  • Deletion — request deletion of your account and all data, via the in-app “Delete account” option or by contacting support.
  • Withdraw consent — disable notification access or stop using the service at any time.

7. ความปลอดภัย7. Security

  • รหัสผ่านถูกเข้ารหัสแบบทางเดียวด้วย PBKDF2 (hashed) — เราไม่สามารถมองเห็นรหัสผ่านจริงของคุณ
  • การรับส่งข้อมูลทั้งหมดเข้ารหัสด้วย HTTPS/TLS ระหว่างการส่ง
  • การเข้าถึงข้อมูลภายในถูกจำกัดเฉพาะที่จำเป็นต่อการให้บริการ
  • Passwords are one-way hashed with PBKDF2 — we cannot see your actual password.
  • All data is encrypted in transit via HTTPS/TLS.
  • Internal access to data is limited to what is needed to operate the service.

8. การเก็บรักษาข้อมูล8. Data retention

เราเก็บข้อมูลของคุณไว้เท่าที่จำเป็นต่อการให้บริการและตามที่กฎหมายกำหนด (เช่น บันทึกการชำระเงินเพื่อการกระทบยอด/บัญชี). เมื่อคุณลบบัญชี เราจะลบหรือทำให้ข้อมูลส่วนบุคคลของคุณไม่สามารถระบุตัวตนได้ภายในระยะเวลาอันสมเหตุสมผล ยกเว้นข้อมูลที่ต้องเก็บตามกฎหมาย. ข้อความการแจ้งเตือนจะถูกประมวลผลเพื่อจับคู่ยอด แล้วเก็บเฉพาะส่วนที่จำเป็น (ยอด/เวลา/แอปต้นทาง) ไม่เก็บเนื้อหาที่ไม่เกี่ยวข้อง.

We retain your data only as long as needed to provide the service and as required by law (e.g. payment records for reconciliation/accounting). When you delete your account, we delete or anonymise your personal data within a reasonable period, except where retention is legally required. Notification text is processed to match amounts, then only the necessary parts (amount/time/source app) are kept — irrelevant content is not stored.

9. ติดต่อเรา9. Contact us

หากมีคำถามเกี่ยวกับนโยบายนี้ หรือต้องการใช้สิทธิ์ของคุณ ติดต่อทีมสนับสนุนได้ผ่าน Cosmixon Hub.

เราอาจปรับปรุงนโยบายนี้เป็นครั้งคราว โดยจะอัปเดตวันที่ “อัปเดตล่าสุด” ด้านบนทุกครั้ง.

For questions about this policy or to exercise your rights, contact our support team via the Cosmixon Hub.

We may update this policy from time to time; the “Last updated” date above will always reflect the latest version.

← กลับหน้าหลัก PayRadar ← Back to PayRadar home

PayRadar · Cosmixon · อัปเดตล่าสุด 20 มิ.ย. 2026Updated 20 Jun 2026