Your privacy and personal data protection are paramount. This policy outlines our transparent data practices in compliance with PDPA (Thailand) and GDPR standards.
Last updated: August 19, 2026Effective date: August 19, 2026
1. Commitment & Overview
Welcome to zPleum. We respect your privacy and are committed to protecting your personal information. This Privacy Policy describes how we collect, process, store, and safeguard your data when you visit our website, interact with our interactive playground modules, or contact us.
We do not sell, rent, or trade your personal data to third parties for marketing or advertising purposes under any circumstances.
2. Information We Collect
We collect information in the following limited categories to provide a fast, secure, and personalized experience:
Anonymous Traffic Telemetry: Anonymized pageviews, cryptographic hash of IP addresses (for unique visitor counting without storing raw IP identifiers), referring URLs, timestamp, browser brand, device type (Desktop, Mobile, Tablet), and operating system.
Direct Inquiries & Communications: When you send an email or message through our contact channels, we receive your name, email address, message body, and any attachments you provide.
Interactive Playground Data: Local temporary parameters (such as restaurant picker preferences or theme configurations) stored directly in your browser's Local Storage.
Authentication Credentials (Administrators Only): Hashed passwords via bcrypt (12 salt rounds), encrypted TOTP 2FA keys, and short-lived session identifiers for authorized administrators.
3. How We Use Your Information
The data collected is utilized solely for legitimate technical and communication purposes:
To deliver, optimize, and maintain website stability and high availability.
To analyze aggregated traffic patterns and identify popular project showcases.
To protect against automated threats, spam, DDoS attacks, and unauthorized access via Cloudflare Turnstile bot detection.
To respond promptly and professionally to inquiries, collaboration offers, and project discussions.
To manage administrator authentication and enforce Two-Factor Authentication (2FA) security protocols.
4. Cookies & Local Storage
We use minimal and strictly essential local storage and cookie mechanisms:
Preferences (Local Storage): Stores your selected theme (Dark/Light mode) and chosen language locale (TH/EN).
Security & Anti-Bot: Cloudflare Turnstile security cookies to distinguish legitimate humans from malicious bots.
Administrative Sessions (HttpOnly Cookies): Secure, encrypted session tokens used exclusively for authenticated administrator dashboard sessions.
We implement enterprise-grade security protocols, including HTTPS (TLS 1.3) data encryption in transit, bcrypt password hashing with high work factors, zero raw IP storage, session expiration timers, and Two-Factor Authentication (TOTP) enforcement.
While no electronic transmission over the Internet is 100% invulnerable, we continuously monitor and patch vulnerabilities to ensure the highest standard of data integrity.
7. Your Rights (PDPA & GDPR)
Under applicable data protection laws including Thailand's Personal Data Protection Act (PDPA) and the European General Data Protection Regulation (GDPR), you hold the following rights:
Right to Access: You may request details of any personal data we hold about you.
Right to Rectification: You may request correction of inaccurate or incomplete information.
Right to Erasure ('Right to be Forgotten'): You may request deletion of your correspondence history or submitted contact data.
Right to Restrict or Object to Processing: You may object to the processing of your personal data.
Right to Withdraw Consent: Where processing relies on consent, you may withdraw it at any time.
8. Contact & Data Controller
OFFICIAL DATA CONTROLLER
If you have questions, feedback, or wish to exercise any of your data protection rights, please contact our Data Controller directly: