Privacy Policy
D2D Guru is operated by D2D Delivery Co., Ltd. (บริษัท ดี2ดี เดลิเวอรี่ จำกัด), company registration number 0775563000846, 129/10 Soi Muban Nong Kae, Nong Kae Sub-district, Hua Hin District, Prachuap Khiri Khan 77110, Thailand. This policy explains what information we handle, why, and what you can ask us to do with it. It is written to meet Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
1. Two groups of people
This policy covers two different relationships:
- Merchants — the shops and restaurants that use D2D Guru. For their account information we are the data controller.
- The merchant's customers— the people who message a merchant's connected account. For those conversations the merchant is the data controller and we act as their data processor: we handle that information on the merchant's instructions, to provide the service the merchant asked for.
2. What we collect from merchants
- Account identity. The email address and shop identity of the D2D Thailand account used to sign in. Sign-in is passed through to the D2D Thailand platform — we do not store your password.
- Connection credentials.The access tokens for the messaging accounts you connect. These are encrypted before they are stored and are used only to send and receive messages for your own connected account. We also store the connected account's display name and username, so you can see which account is connected.
- Your telephone number, when you connect a Telegram account. Telegram signs an account in by telephone number, so connecting one requires yours. It is sent to the Telegram gateway to complete the sign-in; of that number we keep only a masked form, stored with the version and time of the consent you gave. We do not use it to contact you, and it is deleted with the connection. Connecting a bot instead of an account needs no telephone number.
- Settings and usage records. Your assistant configuration, and counts of messages and orders handled, so you can see what the service did on your behalf.
3. What we handle on a merchant's behalf
When a customer messages a merchant's connected account, we handle:
- the messages exchanged between that customer and the merchant, and short summaries of long conversations that let the assistant keep context;
- the identifier the messaging platform assigns to that customer for that merchant's account, and the display name, username and language the platform exposes;
- the details a customer gives in order to place an order — name, phone number, email address where offered, delivery address and any location the customer chooses to share.
We never combine one merchant's conversations with another's. Access is separated per merchant in our database, so a merchant can only ever reach their own records.
4. Information we receive from messaging platforms
When a merchant connects a Facebook Page or an Instagram professional account, the merchant grants us access and we receive from Meta: the list of pages that merchant administers, the connected page's name and picture, and the messages customers send to that page together with the page-scoped identifier of each customer.
We use this information only to:
- let the merchant choose and confirm the correct page;
- receive customer messages sent to that page;
- reply to those customers on the merchant's behalf.
We do not use platform data for advertising or ad targeting, we do not sell it, we do not use it to build profiles unrelated to serving that merchant, and we do not share it between merchants. The same applies to information received from any other messaging platform a merchant connects.
5. Why we are allowed to handle it
- Performance of a contract — to provide the service a merchant signed up for, and to complete an order a customer asked for.
- Legitimate interest — to keep the service secure, prevent abuse, and diagnose faults.
- Consent — where the law requires it, and which you may withdraw at any time.
- Legal obligation — where we must keep records under Thai law.
6. Who else sees the information
We do not sell personal data. We share it only with the parties needed to run the service:
- The AI model providerthat generates the assistant's replies. Message text and conversation context are sent to it to produce a reply. We currently use Z.ai. The provider processes the text to return a reply and is not permitted to use it for its own purposes.
- The D2D Thailand order platform, which receives the order details needed to fulfil and deliver an order. Once a customer verifies their phone number, we also look up their existing orders and saved delivery addresses at that shop, so the assistant can offer them instead of asking again.
- Google (Firebase), which delivers the SMS code when a customer chooses to verify their phone number. To do so it receives that phone number for the duration of the verification. We keep the verified status, the time of verification, and the verification record itself (which includes the number), stored with the merchant's conversation record and deleted with it.
- The messaging platform the conversation takes place on, which necessarily carries the messages.
- Our hosting provider, which runs the servers storing this information.
- Authorities, where we are legally required to disclose information.
7. Where it is stored and for how long
- Connection credentials, the masked telephone number and the consent record are deleted when a merchant disconnects the channel or closes their account.
- Conversations and customer detailsare kept while the merchant's account is active, because the merchant needs the history to serve returning customers, and are deleted on request or when the account is closed.
- Records we must keep by law, such as order and accounting records, are kept for the period the law requires.
8. How it is protected
Credentials are encrypted before storage and are never displayed back, even to the merchant who supplied them. Traffic is served over HTTPS. Each merchant's records are isolated at the database level. Message text, phone numbers, addresses and credentials are excluded from our operational logs.
9. Your rights
Under the PDPA you may ask us to:
- tell you what information we hold about you and give you a copy;
- correct information that is wrong or incomplete;
- delete information, or restrict what we do with it;
- withdraw a consent you gave;
- object to a particular use;
- complain to Thailand's Personal Data Protection Committee.
Write to admin@d2d.guru. We answer within 30 days. If you are a customer of a merchant, you may also ask that merchant directly — they decide what happens to their conversations, and we act on their instruction.
10. Deleting your data
Instructions, including how to delete information we received from Facebook or Instagram, are on the data deletion page.
11. Children
D2D Guruis a tool for businesses and is not directed at children. We do not knowingly collect information from children. If you believe a child's information reached us, write to us and we will delete it.
12. Changes to this policy
We update this page when our practices change and revise the date at the top. Material changes are announced to merchants in the dashboard.
13. Contact
D2D Delivery Co., Ltd. (บริษัท ดี2ดี เดลิเวอรี่ จำกัด)Company registration number 0775563000846
129/10 Soi Muban Nong Kae, Nong Kae Sub-district, Hua Hin District, Prachuap Khiri Khan 77110, Thailand
Email: admin@d2d.guru
Telephone: +66 61 381 0383
