NikahMe

Privacy Policy

Version 1.4-2026-07-27 · Effective July 27, 2026 · อ่านภาษาไทย

This document says what we collect, what we do with it, who sees it, and what rights you have, under Thailand's Personal Data Protection Act B.E. 2562 (2019). We wrote it truthfully — both what we can protect and the limits that exist — because you should decide on facts, not marketing.

1. Who controls your data

The data controller is Mr. Affan Kasemsan (owner and operator of the NikahMe platform). For anything about your personal data, contact privacy@nikahme.app.

2. What we collect

First, what we deliberately never ask for: legal first or last names, national ID numbers, identity documents, or photos. Every “name” field in the system is a call-name or alias you choose yourself. If you type your real name in anyway, the system stores what you typed — but we never require it and don't recommend it. Here is what we actually keep:

  • Account: email, password (always stored as a hash, unreadable to anyone), the username and call-name you set, gender, your Google account if you sign in with Google, and your settings.
  • L1 profile (summary): age range, region, marital status, marriage intent and timeline, occupational field, relocation flexibility, languages, religious approach, religious education, and religious appearance.
  • L2 profile (detail): date of birth, province, occupation and relocation detail, your introduction text, prompt answers, and the representative or coordinator contact channel you entered.
  • Coordinators: a call-name, a contact channel (LINE, phone, etc.), and contact boundaries, as you or they entered them.
  • Usage: exchange requests and their status, saved profiles, outcome reports (such as “married”), support tickets, appeals, and last-active time (that last one is shown to no one).
  • Technical: push notification subscription data, and system logs which may include IP addresses, kept for security and troubleshooting.

One more thing we deliberately don't store: the substance of any “advance disclosure” matter, such as a health condition. The system keeps only a “has / none” signal; the substance is meant to be shared verbally through the coordinator.

3. Sensitive data and explicit consent

Data about religion — your approach, education, appearance, and identifying as Muslim — is sensitive data under Section 26 of the PDPA. We may keep and use it only with your explicit consent, which you give by ticking the box at sign-up and by choosing to enter it yourself. Plainly: religious data is the heart of this service. Without it, the profile features can't work — and you can withdraw consent whenever you want (see Section 9).

The “advance disclosure” signal is volunteered by you, used for display only, and never used as a filter or in search.

4. What we use data for, and on what legal basis

  • Running the core service: accounts, profiles, introductions, exchange requests, and contact coordination (contract; explicit consent for sensitive data).
  • Verifying email and recovering accounts, via email OTP codes (contract).
  • Keeping the system safe: preventing fraud and misuse, reviewing reports (legitimate interests).
  • Notifications in-app, by email, and by push — adjustable or disableable in settings (contract).
  • Complying with law and lawful orders of state authorities (legal obligation).
  • Looking at aggregate usage to improve the system, summarized or anonymized where possible (legitimate interests).

We do not sell your data, and we do not use it for anyone's advertising.

5. Who sees what, and when

Between users, visibility follows the layers the system is built on:

  • L1 (summary) is visible through channels you enable — your introduction card, or the discovery feed if you opt in.
  • L2 (detail) opens to the other side only once both of you have accepted the exchange request.
  • Contact channels open by the system's steps, through the coordinator you set up.
  • Both sides' coordinators see what coordination requires, including the relevant contact channels.

And on our side — to be direct: your data lives on our servers, and the system has to be able to read it to work at all, for matching and display. The team operating the system therefore has the technical ability to access data when genuinely necessary — debugging, reviewing a reported case, or complying with law. We keep that access down to what each job requires, we have no practice of accessing anyone's data without a necessary reason, and your password is readable by no one, including us, because it is always stored as a one-way hash.

State authorities get data only where the law requires it or a lawful order compels it.

6. Service providers and data leaving the country

We don't build everything ourselves. The system relies on these providers, which process data on our instructions:

  • Neon (US/EU) — the system's database, encrypted at rest.
  • Render (US) — backend server hosting.
  • Vercel (US) — hosting for the website itself, and visit statistics for public pages only (page views, country, referring site). Pages behind login are not collected, and profile share links have their code stripped before sending.
  • Resend (US) — email delivery, such as OTP codes; it therefore sees email addresses and the content of emails sent.
  • Google (US) — only if you choose to sign in with Google.
  • Browser push providers such as Google, Apple, and Mozilla — for notifications you subscribe to.
  • Cloudflare (US) — bot protection (Turnstile) at certain steps.
  • PostHog (EU) — usage statistics. It receives only events we define in advance, as a closed list, in two parts: (a) on public pages — which page was opened, waitlist signed, sign-up completed — paired with a random per-browser id not tied to any account; (b) inside the signed-in product, our server sends five events: sign-up completed, profile readiness advanced, exchange requested, exchange accepted, and outcome reported, using an id derived from your account by a one-way transformation, so PostHog never receives an identifier that maps back to you in our systems. No tracking script runs on pages behind login, there is no session recording, we send no name, email, gender or profile answer of any kind, and profile share links have their code stripped before sending.

These providers are abroad, so using NikahMe involves data leaving Thailand. We pick providers with recognized data protection standards, and we list them here so you can see them before deciding to use the service.

7. Security — what we do, and its honest limits

What is in place today:

  • Passwords are one-way hashes. No one can recover the original, including us.
  • Everything in transit is encrypted over HTTPS.
  • The database is encrypted at rest by the provider.
  • The L1/L2 disclosure layers are enforced on the server, not merely hidden in the interface.
  • System access is restricted by role, and we keep reviewing this.

The limit, said plainly: no system on earth is one hundred percent secure, and because the system must be able to read data to match you with anyone, profile data is not encrypted in a way that even we cannot read. If a breach happens that puts you at high risk, we will notify Thailand's Personal Data Protection Committee within 72 hours as the law requires, and tell you without delay.

8. How long we keep things

  • Account and profile: kept while the account is active.
  • When you ask us to delete your account, personal data is erased or irreversibly anonymized within 90 days — unless the law requires longer, or a dispute is still open.
  • Expired exchange requests (past 7 days) lose effect immediately; the record is kept on the normal cycle for security and audit.
  • System logs are kept briefly for security and troubleshooting, then deleted or rotated automatically.
  • Anything the law says to keep, we keep for as long as that law says.

9. Your rights

Under the PDPA you have all of these, free of charge:

  • Access your data and get a copy.
  • Have it corrected and kept current.
  • Have it erased or anonymized.
  • Have its use temporarily suspended.
  • Object to its collection, use, or disclosure.
  • Receive it, or have it transferred, in a machine-readable format.
  • Withdraw consent at any time. What was already lawfully processed doesn't reverse, but services that depend on that data may stop being usable.
  • Complain to Thailand's Personal Data Protection Committee if you believe we've broken the law.

To exercise any of these, write to privacy@nikahme.app. We will act within 30 days of receiving your request, and may first ask you to confirm it's really you — so no one else can impersonate you to get at your data.

10. What sits in your browser

We use browser storage (local storage) to keep you signed in and to remember settings like theme and language — things the service needs to function — and to hold one random id used for counting visits to public pages. That id is not tied to your account and clearing your browser data removes it. We use no tracking cookies for advertising. Some external services, like Cloudflare's bot protection, may set their own cookies under their own terms.

11. Minors

This place is only for people aged 18 and over. We do not knowingly keep data on anyone younger. If we find an underage account, we delete it and its data.

12. When this policy changes

We may adjust this policy from time to time. The current version and effective date are always on this page. For material changes — especially using data for a new purpose — we will tell you, and ask for fresh consent where the law requires it.

13. Contact us

Data controller: Mr. Affan Kasemsan (owner and operator of the NikahMe platform), email privacy@nikahme.app — for all questions, rights requests, or complaints about personal data.