Privacy Policy
Last updated: 21 August 2026
อ่านฉบับภาษาไทย1. Data controller
Harun Sangrompo (operator of CandleStonk) — contactable at support@candlestonk.com
- Data Protection Officer: none appointed. The service does not meet the conditions in section 41 of the PDPA that require one — it is not a public authority, large-scale systematic monitoring is not its core activity, and it does not process sensitive data as a core activity. If the scope of the business changes so that it does, we will appoint one and say so here.
- Representative in the Kingdom: none. The controller is already located in Thailand, so section 37(5) does not apply.
2. What we collect
| Type | Examples | Source |
|---|---|---|
| Account data | Name, email, profile picture | Google OAuth at sign-in — collected directly from you |
| Trading data | Symbols, entry/exit prices, size, dates, your own notes, tags, deposits and withdrawals | Entered by you |
| Payment data | The transfer slip you send to confirm a Supporter payment | Sent by you by email — there is no automatic charging |
| Usage data | Access and error logs (for security and troubleshooting) | Recorded automatically |
All of the above is collected directly from the data subject. We do not buy your data or obtain it from anywhere else, and we do not collect sensitive data under section 26 (race, religion, health, biometrics and so on). Please do not enter anything of that kind into the notes fields.
3. Purposes and lawful bases
We use your data only for the following purposes:
- To provide the trade-recording and analysis service you asked for — basis: necessary for performance of a contract (section 24(3))
- To authenticate you and keep your account secure — basis: performance of a contract, and legitimate interest (section 24(5))
- To check and confirm a Supporter payment — basis: necessary for performance of a contract
- To contact you about important changes to the service, such as changes to the terms or the start of charging — basis: necessary for performance of a contract
- To publish your results as a public profile only where you switch that on yourself (see section 7) — basis: consent (section 19), which you can withdraw at any time by switching back to private. Withdrawing it does not affect the rest of the service.
We do not use your data for marketing, advertising or cross-site behavioural analysis, and there is no automated decision-making with a significant effect on you under section 32(4).
4. What happens if you do not provide data
Your email and Google account details are necessary to enter into the agreement — without them you cannot sign up or sign in. Trading data is provided voluntarily; without it the basic service still works, but there is nothing for the statistics to be calculated from.
5. How long we keep it
- For as long as the account is in use.
- If you ask to close your account, the data is deleted within 30 days — those 30 days exist so it can be restored if you change your mind — unless another law requires longer, for example tax records under the Revenue Code.
- Access and error logs are kept for no more than 90 days, then deleted automatically.
- Backups are kept for no more than 90 days from the date each copy was made, then deleted. If you ask for your account to be deleted in the meantime, your data is removed from the live system immediately as above; backups made earlier expire and are deleted on the 90-day cycle.
6. Disclosure to third parties
We do not sell your personal data. It is passed only to the data processors necessary to run the service:
- Google LLC — for signing in with a Google account.
- Turso (a US company) — database provider.
- hostatom.com (Thailand) — web application hosting.
- frankfurter.dev(publishes the European Central Bank's reference rates) — we call it to fetch daily exchange rates into our own database. That call sends only a date range and a currency pair. No personal data of any user leaves the system. This provider is therefore not one of our data processors, but is listed for transparency.
- Payments: currently no external payment provider is involved at all. You transfer by PromptPay directly and email us the evidence, so no payment data of yours reaches a third party through us. When card payment opens for customers outside Thailand it will be handled by Stripe, which will then be a processor for the data you give it — we will update this section and tell you before that happens, not after.
We may also disclose data on a lawful order from a government authority or a court, or where necessary to protect the rights and safety of other users.
7. Public profile (published by you)
You may choose to publish your own results as a profile page under Settings → Public profile. It is off by defaulton every account and can only be turned on by you. We never publish anyone's data without them asking for it.
Once on, the profile page shows only:
- Monthly and yearly returns, as percentages
- Number of closed trades, win rate, profit factor and average holding time
- If you have several portfolios, you choose which single one is published; the rest do not appear on that page at all. If the published portfolios are in different currencies, monthly returns and profit factor are not shown, because combining across currencies would mean nothing.
- Open positions — symbol, direction, and size as a percentage of capital (entry prices appear only if you turn on a second switch).
- The 20 most recent closed trades, with profit or loss as a percentage, and dates
- The display name and bio you wrote yourself
Never published: your email, your Google account name, your account balance, deposits and withdrawals, position sizes in money, notes, tags, action plans and portfolio names.
There are three levels:
- Anyone with the link — no sign-in needed, not indexed by search engines, but whoever has the link can pass it on.
- Invited people only — visible only to the accounts whose emails you list, and they must sign in. A forwarded link will not open.
- Public — everyone, including search engines.
You can switch it back off at any time, and it takes effect immediately, because the setting is re-checked every time someone opens the page.
If you invite people: the emails you enter are stored only to check who may view the page. They are not emailed, not used for marketing, and are deleted as soon as you remove the person or close your account. Invite only people you know and are happy to have see your data.
Please consider before publishing that anything made visible can be screenshotted or copied by others, which is beyond our control.
8. Transfers abroad
The web application is hosted in Thailand (hostatom.com), but some data is sent to or processed by providers abroad:
- Main database: stored on Turso servers located in Tokyo, Japan (region ap-northeast-1).
- Google sign-in: your name, email and profile picture are processed by Google LLC, which has data centres in the United States and other countries.
These transfers rely on sections 28–29: they are necessary for the performance of a contract to which you are a party, and we choose providers with data protection measures meeting international standards.
9. Security
- All data is transmitted over encrypted HTTPS/TLS.
- The application reaches the database with a dedicated token; the database is not open to outside access.
- Each account can reach only its own data, separated from other accounts at the query level.
- We hold no user passwords at all, because authentication is entirely through Google.
- The administrator can access data as far as is necessary to run the service — checking user counts, confirming payments, and investigating problems people report.
Backups: to guard against data loss, the administrator makes occasional copies of the whole database. Those copies are kept on the administrator's own computer in Thailand, are not uploaded to any public cloud service, are not shared with anyone, and are deleted on the schedule in section 5. We state this plainly because those copies sit outside the application, which makes them something you should know exists.
In the event of a personal data breach we will notify the Personal Data Protection Committee within 72 hours of becoming aware of it, and where the breach carries a high risk to your rights and freedoms we will notify you without delay, together with what can be done about it (section 37(4)).
9a. If you are in the EU, the EEA or the UK
The service is offered worldwide, which means the GDPR (and the UK GDPR) applies to people in those places even though we are established in Thailand. Everything above still describes what we do; this section says what it is called under those rules and what extra rights you have.
Legal bases (GDPR Article 6), mapping onto the purposes in section 3:
- Providing the service, authenticating you and confirming a payment — Article 6(1)(b), necessary for a contract with you
- Keeping the service secure and troubleshooting faults — Article 6(1)(f), our legitimate interest in a working, non-abused service
- Publishing your public profile, if you switch it on — Article 6(1)(a), your consent, withdrawable at any time
Transfers out of the EEA/UK. Your data is stored on servers in Japan and processed in Thailand, and Google processes sign-in data in the United States and elsewhere. Japan has an adequacy decisionfrom the European Commission and is recognised as adequate by the UK. For transfers to Thailand and to other providers without adequacy, we rely on the European Commission's Standard Contractual Clauses(and the UK Addendum) as incorporated in those providers' data processing terms. You may ask us for details of the safeguards that apply.
Your rights are the same list as section 10 — access, rectification, erasure, restriction, portability, objection and withdrawal of consent — under GDPR Articles 15 to 22 rather than the PDPA sections cited there. You also have the right to lodge a complaint with your own supervisory authority: the data protection authority of the EU or EEA country you live in, or the Information Commissioner's Office in the UK. You do not have to come to us first, although we would rather you did so we can fix it.
Representative under Article 27.We have not appointed an EU or UK representative. Our processing of EU and UK residents' data is occasional, is not large-scale, involves no special-category data, and is unlikely to result in a risk to your rights and freedoms — which is the exemption in Article 27(2)(a). If that stops being true as the service grows, we will appoint one and name them here.
Automated decision-making: none. Nothing about your account is decided by an algorithm in a way that produces legal or similarly significant effects (Article 22).
10. Your rights under the PDPA
As a data subject you have the right:
- to withdraw consent at any time (section 19, paragraph five);
- to access and obtain a copy of your data (section 30);
- to data portability to another controller (section 31);
- to object to collection, use or disclosure (section 32);
- to erasure — the “right to be forgotten” (section 33);
- to restriction of use (section 34);
- to rectification, keeping data accurate and up to date (section 36);
- to lodge a complaint with the Personal Data Protection Committee (section 73).
11. How to exercise your rights
- Most trading data you can edit or delete yourself, immediately, in the app — no need to contact us.
- For anything else (a copy of your data, portability, permanent account deletion and so on) email support@candlestonk.com from the address you signed up with.
- We act within 30 days of receiving the request, as section 30 paragraph four requires. If we refuse, we give the reason in writing.
- Exercising these rights is free.
If you are not satisfied with how we handle it, you may complain to the Personal Data Protection Committee (PDPC).
12. Minors
This service is intended for people of legal age (20 years). If you are a minor you need the consent of a person with parental authority before using the service and before providing personal data (section 20). If we learn that a minor's data has been collected without proper consent, we delete it immediately.
13. Cookies
We use only the cookies the service needs to function: your sign-in state, your chosen language, and your chosen theme. There are no advertising or tracking cookies, and no third-party analytics.
14. Changes to this policy
We may revise this policy from time to time. For a material change we will give at least 30 days' notice by email or in the app, and the date it was last updated is always shown at the top of this page.
15. Contact
For questions about this policy or about how your personal data is used, write to support@candlestonk.com
If you are in the EU, the EEA or the UK and are not satisfied with our answer, you can go to your own supervisory authority — see section 9a.
See also our Terms of Service