Privacy · private launch
เก็บเท่าที่ต้องใช้
แยก purpose และลบได้จริง
นโยบายสำหรับ Wheel Teller Community & Polls Production V1 อัปเดตล่าสุด 31 กรกฎาคม 2026 เว็บยังใช้ noindex, nofollow
ข้อมูลบัญชีและ Community
- บัญชี: Google OAuth และ Supabase Auth จัดการอีเมล/identity/session; Community ใช้ UUID และชื่อที่แสดง ไม่เปิดชื่อ อีเมล หรือรูป Google ต่อสาธารณะ
- เนื้อหา: topic, comment/reply, revision, tombstone, Helpful/Disagree, report, moderation notice, appeal, subscription, notification และ preference
- ความปลอดภัย: rate/security event, role/restriction, audit receipt และหลักฐานที่จำเป็นต่อการทบทวน โดยไม่เปิด reporter หรือ risk signal ให้ผู้ใช้รายอื่น
- เบราว์เซอร์: theme, session และ local recovery draft แบบจำกัดอายุ/ขนาด Draft อยู่ในอุปกรณ์จนส่งสำเร็จ ลบเอง หมดอายุ หรือล้าง site data
โพล: Member และ Guest แยกกันเสมอ
คำตอบ Member ผูกกับ actor ภายในเพื่อแก้/ถอน/ส่งออกได้ ส่วน Guest (เมื่อ gate ผ่าน) ใช้ anonymous Supabase session, Cloudflare Turnstile และ signed assertion จาก Gateway เราอาจใช้ IP-HMAC แบบหมุนกุญแจ, coarse device/channel และ risk decision เพื่อกัน abuse แต่ไม่ขาย identifier หรือรวม Member/Guest เพื่อข้าม low-n threshold
เก็บเวลาที่เห็นคำเชิญ เริ่ม ส่ง ถอน และ completion time; skipped/missing, ลำดับตัวเลือกที่เห็น, series/target และผลก่อนตอบเฉพาะเท่าที่ใช้วัดคุณภาพ Raw telemetry เก็บ 90 วันแล้วสรุปเป็น aggregate และไม่สร้าง individual browsing product
Research และ sponsored ต้องมี consent แยก purpose
Community consent ไม่รวม research/commercial consent ก่อนตอบต้องแสดง notice version, purpose, recipient/บทบาท sponsor, data use และให้ self-declare อายุ 18+ Production V1 ไม่ถือ Google account เป็นหลักฐานอายุ Demographic เป็นข้อมูลสมัครใจแบบหมวดกว้างและ snapshot ณ เวลาตอบ; ไม่ถามข้อมูลอ่อนไหวหรือข้อมูลที่ระบุตัวบุคคล
เมื่อถอน consent ระบบทำเครื่องหมาย response/snapshot ว่าใช้ต่อไม่ได้ กัน processing/export ใหม่ และ rebuild aggregate ก่อนเผยแพร่รอบถัดไป Aggregate ที่ anonymized แบบย้อนกลับไม่ได้และเผยแพร่ไปแล้วอาจเรียกคืนรายคนไม่ได้
ใช้ข้อมูลเพื่ออะไร และสิ่งที่ไม่ทำ
ใช้เพื่อให้บริการบัญชี/ชุมชน, moderation/security, ส่ง notification ที่เลือกไว้, วัดคุณภาพโพล และ—เฉพาะเมื่อ gate/consent/สัญญาผ่าน—research หรือ aggregate insight เราไม่ขาย raw vote, answer, comment, optional text, email, Google identity, user ID, IP/device identifier, persistent pseudonym, moderation/risk signal หรือ browsing history และไม่ให้ sponsor ดู raw data แก้ wording หลังเปิด ซ่อนผล หรือ moderate discussion
ผู้ให้บริการและการส่งข้อมูล
- Google: OAuth identity
- Supabase: Auth และฐานข้อมูล PostgreSQL/RPC
- Hostinger: static site และ Node Gateway บน production host
- Cloudflare Turnstile: challenge สำหรับ Guest เมื่อ capability เปิด
- NAS/offsite recovery: encrypted backup ที่จำกัดผู้เข้าถึงและต้อง replay deletion ledger หลัง restore
บริการอาจประมวลผลนอกประเทศไทยตามโครงสร้างของผู้ให้บริการ ก่อนเปิด research/commercial ต้องทบทวน DPA, subprocessor, cross-border transfer, lawful basis และบทบาท controller/processor ของแต่ละโครงการ
ระยะเก็บเริ่มต้น
| ข้อมูล | ระยะเริ่มต้น |
|---|---|
| Public UGC, poll definition, methodology, aggregate | อย่างน้อย 2 ปี และต่อเนื่องตราบที่ยังเผยแพร่หรือมีเหตุผล |
| Raw casual poll response | 2 ปีหลังปิด แล้ว detach linkage และคง anonymized aggregate |
| Raw research/commercial + demographic | ไม่เกิน 2 ปีหลังปิด หรือหยุดใช้เมื่อถอน consent แล้ว re-aggregate |
| Profile/Auth | ขณะใช้งาน; delete account ลบ PII/draft/pending และ anonymize published |
| Helpful/Disagree state และ events | อย่างน้อย 2 ปีหลัง target มีกิจกรรมล่าสุด/ถูก archive; delete แล้ว detach actor |
| IP-HMAC | 90 วัน |
| Detailed rate/security event | 30 วัน แล้วเหลือ aggregate |
| Poll exposure/order/completion telemetry | 90 วันแบบ raw แล้ว aggregate |
| Reports, moderation evidence, appeals, privileged audit | 2 ปีหลังปิดเคส |
| Notification | 180 วัน |
| Consent/withdrawal receipt | ตลอดช่วงใช้ข้อมูล + อย่างน้อย 2 ปีหลังหยุดใช้ หรือเท่าที่กฎหมายจำเป็น |
| Deletion/withdrawal ledger + key/version map | อย่างน้อยจน backup เก่าสุดหมดอายุบวก restore/audit window; key map อยู่ใน encrypted/offline recovery kit |
| Full encrypted DR backup | daily 30, weekly 12, monthly 24; restore ต้อง replay deletion ledger |
| Sanitized aggregate export | แยกจาก DR backup และเก็บตามอายุ public/commercial product |
สิทธิ์ ส่งออก และการลบบัญชี
เมื่อ self-service gate เปิด คุณขอ JSON machine-readable ของ profile, own content/revisions, own poll answer/revisions และ demographic snapshot, consent/withdrawal, subscriptions/preferences, own reports/appeals, moderation notices และ telemetry ของตนที่ยังอยู่ใน retention โดยไม่รวมข้อมูลหรือ risk signal ของคนอื่น
Account deletion ต้อง OAuth re-auth ใหม่และ durable ledger acknowledgement: hard-delete draft/pending/PII/OAuth linkage, revoke session, anonymize published UGC, detach response/actor/data-subject mapping และ recompute aggregate ที่ได้รับผล Backup restore ทุกครั้งต้อง replay ledger เพื่อไม่ให้ข้อมูลที่ลบกลับมา Internal privacy-request SLA คือ 30 วัน พร้อมบันทึกเหตุเมื่อจำเป็นต้องขยายหรือปฏิเสธตามกฎหมาย
เหตุข้อมูลส่วนบุคคล
เมื่อสงสัยเหตุ ระบบจะปิด write/endpoint ที่เกี่ยวข้อง, rotate/revoke secret หรือ session, รักษาหลักฐาน, ระบุชนิดและผู้ได้รับผล, ประเมินความเสี่ยง และบันทึกเวลาที่รับรู้เหตุ การแจ้งจะยึดข้อเท็จจริงและข้อกำหนดที่ใช้บังคับ