1. Data Controller & Contact
The data controller for the information described in this policy is the Ellen Joe Bot Team. For any privacy request, question, or complaint, contact us via our Discord support server or by email at contact.chatkawin@gmail.com.
2. Information We Collect
To operate the Service, we collect and store:
- Your Discord User ID, used as the primary key for your account record.
- Your HoYoLab login cookies (specifically
ltoken_v2andltuid_v2). - Your selected games and your subscription expiry date.
- Data appearing on your payment slip when you subscribe (account holder name, bank account/PromptPay number, amount, transaction reference, and timestamp), which is sent to our slip-verification processor for validation.
3. How We Use This Data & Legal Basis
- Discord ID, cookies, selected games, and expiry date are used exclusively to operate your paid subscription (perform daily check-in API calls to HoYoLab and track your active period). Legal basis: necessary for the performance of a contract with you.
- Payment-slip data is used to verify your transaction and prevent fraud/duplicate use. Legal basis: contract performance and fraud prevention.
- Discord IDs of users blacklisted for fraudulent slips are retained to prevent repeat abuse. Legal basis: our legitimate interest in protecting the Service from fraud.
- We do not use your data for any purpose beyond those listed above.
4. Third Parties & Cross-Border Transfers
We do not sell your data. We do share specific data with the following processors, each necessary to operate the Service, and each located outside Thailand:
- Cloudflare — hosts our infrastructure and database (Cloudflare KV); stores your Discord ID, cookies, games, and expiry date.
- EasySlip / SlipOK (our slip-verification provider) — receives your payment slip image and transaction details to verify the transfer.
- HoYoLab / HoYoverse — receives your HoYoLab cookies as part of the daily automated check-in API request; this is the intended function of the Service.
- Discord — the platform through which the Service is delivered and through which we send you check-in result notifications.
Because these processors operate outside Thailand, using the Service involves the cross-border transfer of your data to them as necessary to provide the Service to you.
5. Data Storage and Security
- Cookies and account data are stored in a private, encrypted Cloudflare KV database.
- Access is restricted to the automated check-in system and to the personnel who need it to operate the Service — not to arbitrary staff or the public.
- You can update or clear your cookies at any time using the
/checkin-setupcommand.
6. Data Retention
- HoYoLab cookies and account records are deleted within 90 days after your subscription expires, unless you delete them sooner yourself.
- Payment evidence (slip records, transaction references) is retained for 5 years for financial record-keeping purposes.
- Blacklist records are retained for as long as necessary to prevent repeat fraud.
7. Your Rights
Subject to applicable law, you have the right to: access and request a copy of your data; request correction of inaccurate data; request deletion; request restriction of processing; object to processing; withdraw consent where processing is based on consent; request data portability; and lodge a complaint with Thailand's Personal Data Protection Committee (PDPC). To exercise any of these rights, contact us via the channels in Section 1.
Note: withdrawing consent or requesting deletion means the Bot can no longer perform check-ins for you, since your cookies are necessary for that function. This does not retroactively entitle you to a refund under our no-refund policy (see Terms of Service, Section 3).
8. Data Breach Notification
In the event of a data breach, we will notify Thailand's PDPC within 72 hours of becoming aware of it where required by law, and will notify affected users without undue delay where the breach poses a high risk to their rights — for example, a leaked session cookie, which could directly allow access to your game account.
9. Account Deletion
If you wish to remove your data completely, you can delete your cookies via the setup command or contact us using the channels in Section 1 to request deletion of your database entry.
🇹🇭 ฉบับภาษาไทย (Thai Version)
1. ผู้ควบคุมข้อมูลและช่องทางติดต่อ
ผู้ควบคุมข้อมูล (Data Controller) สำหรับข้อมูลตามนโยบายนี้คือ Ellen Joe Bot Team หากต้องการใช้สิทธิ์เกี่ยวกับข้อมูลส่วนบุคคล สอบถาม หรือร้องเรียน สามารถติดต่อเราผ่าน Discord support server หรืออีเมล contact.chatkawin@gmail.com
2. ข้อมูลที่เราเก็บรวบรวม
เพื่อให้บริการนี้ทำงานได้ เราเก็บรวบรวมและจัดเก็บข้อมูลดังนี้:
- Discord User ID ของคุณ ใช้เป็นคีย์หลักของบัญชี
- คุกกี้ล็อกอิน HoYoLab ของคุณ (โดยเฉพาะค่า
ltoken_v2และltuid_v2) - เกมที่คุณเลือก และ วันหมดอายุสมาชิก
- ข้อมูลที่ปรากฏบนสลิปโอนเงินเมื่อคุณสมัครสมาชิก (ชื่อผู้โอน, เลขบัญชี/PromptPay, ยอดเงิน, เลขอ้างอิงธุรกรรม และเวลาที่ทำรายการ) ซึ่งถูกส่งไปยังผู้ให้บริการตรวจสอบสลิปของเราเพื่อยืนยันความถูกต้อง
3. วัตถุประสงค์การใช้ข้อมูลและฐานทางกฎหมาย
- Discord ID, คุกกี้, เกมที่เลือก และวันหมดอายุ ใช้เพื่อดำเนินการสมาชิกที่คุณชำระเงินไว้เท่านั้น (เรียก API เช็คอินรายวันกับ HoYoLab และติดตามระยะเวลาสมาชิกของคุณ) ฐานทางกฎหมาย: จำเป็นเพื่อการปฏิบัติตามสัญญากับคุณ
- ข้อมูลสลิปโอนเงิน ใช้เพื่อตรวจสอบธุรกรรมและป้องกันการฉ้อโกง/การใช้ซ้ำ ฐานทางกฎหมาย: การปฏิบัติตามสัญญา และ การป้องกันการฉ้อโกง
- Discord ID ของผู้ใช้ที่ถูกขึ้นบัญชีดำ (Blacklist) จากการส่งสลิปปลอม จะถูกเก็บไว้เพื่อป้องกันการกระทำผิดซ้ำ ฐานทางกฎหมาย: ประโยชน์โดยชอบด้วยกฎหมายของเราในการปกป้องระบบจากการฉ้อโกง
- เราไม่นำข้อมูลของคุณไปใช้เพื่อวัตถุประสงค์อื่นนอกเหนือจากที่ระบุไว้ข้างต้น
4. บุคคลที่สามและการโอนข้อมูลไปต่างประเทศ
เราไม่ขายข้อมูลของคุณ แต่มีการส่งข้อมูลบางส่วนให้ผู้ให้บริการภายนอกต่อไปนี้ ซึ่งจำเป็นต่อการให้บริการ และตั้งอยู่นอกประเทศไทยทั้งหมด:
- Cloudflare — โฮสต์ระบบและฐานข้อมูล (Cloudflare KV) ของเรา จัดเก็บ Discord ID, คุกกี้, เกม และวันหมดอายุของคุณ
- EasySlip / SlipOK (ผู้ให้บริการตรวจสอบสลิปของเรา) — รับภาพสลิปและรายละเอียดธุรกรรมของคุณเพื่อตรวจสอบการโอนเงิน
- HoYoLab / HoYoverse — รับคุกกี้ HoYoLab ของคุณ ในการเรียก API เช็คอินอัตโนมัติรายวัน ซึ่งเป็นหน้าที่หลักของบริการนี้
- Discord — แพลตฟอร์มที่ใช้ให้บริการและส่งการแจ้งเตือนผลเช็คอินให้คุณ
เนื่องจากผู้ให้บริการเหล่านี้ตั้งอยู่นอกประเทศไทย การใช้บริการนี้จึงมีการโอนข้อมูลของคุณไปต่างประเทศเท่าที่จำเป็นต่อการให้บริการแก่คุณ
5. การจัดเก็บและความปลอดภัยของข้อมูล
- คุกกี้และข้อมูลบัญชีถูกจัดเก็บในฐานข้อมูล Cloudflare KV แบบเข้ารหัสและเป็นส่วนตัว
- จำกัดการเข้าถึงเฉพาะระบบเช็คอินอัตโนมัติและบุคลากรที่จำเป็นต่อการให้บริการเท่านั้น ไม่ใช่พนักงานทั่วไปหรือบุคคลภายนอก
- คุณสามารถอัปเดตหรือลบคุกกี้ของคุณได้ทุกเมื่อ ผ่านคำสั่ง
/checkin-setup
6. ระยะเวลาการเก็บข้อมูล
- คุกกี้ HoYoLab และข้อมูลบัญชีจะถูกลบภายใน 90 วัน หลังสมาชิกหมดอายุ เว้นแต่คุณจะลบเองก่อนหน้านั้น
- หลักฐานการชำระเงิน (สลิป, เลขอ้างอิงธุรกรรม) จะถูกเก็บไว้ 5 ปี เพื่อวัตถุประสงค์ด้านบันทึกทางการเงิน
- ข้อมูล Blacklist จะถูกเก็บไว้ตราบเท่าที่จำเป็นต่อการป้องกันการฉ้อโกงซ้ำ
7. สิทธิของเจ้าของข้อมูล
ภายใต้กฎหมายที่เกี่ยวข้อง คุณมีสิทธิ: เข้าถึงและขอสำเนาข้อมูล, ขอแก้ไขข้อมูลที่ไม่ถูกต้อง, ขอลบข้อมูล, ขอระงับการประมวลผล, คัดค้านการประมวลผล, เพิกถอนความยินยอมในกรณีที่ใช้ฐานความยินยอม, ขอโอนย้ายข้อมูล และร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.) หากต้องการใช้สิทธิ์ใดๆ ข้างต้น กรุณาติดต่อเราตามช่องทางในหัวข้อ 1
หมายเหตุ: การเพิกถอนความยินยอมหรือขอให้ลบข้อมูล หมายความว่าบอทจะไม่สามารถเช็คอินให้คุณได้อีกต่อไป เนื่องจากคุกกี้ของคุณจำเป็นต่อการทำงานนี้ และการเพิกถอนดังกล่าวไม่มีผลย้อนหลังทำให้คุณได้รับสิทธิ์คืนเงินตามนโยบายไม่คืนเงิน (ดู Terms of Service หัวข้อ 3)
8. การแจ้งเหตุข้อมูลรั่วไหล
หากเกิดเหตุข้อมูลรั่วไหล เราจะแจ้งต่อ สคส. ภายใน 72 ชั่วโมงนับจากที่เราทราบเหตุตามที่กฎหมายกำหนด และจะแจ้งผู้ใช้ที่ได้รับผลกระทบโดยไม่ชักช้า หากเหตุนั้นมีความเสี่ยงสูงต่อสิทธิของผู้ใช้ เช่น คุกกี้ session รั่วไหล ซึ่งอาจนำไปสู่การเข้าถึงบัญชีเกมของคุณได้โดยตรง
9. การลบบัญชี
หากต้องการลบข้อมูลของคุณทั้งหมด คุณสามารถลบคุกกี้ผ่านคำสั่งตั้งค่า หรือติดต่อเราตามช่องทางในหัวข้อ 1 เพื่อขอให้ลบข้อมูลของคุณออกจากฐานข้อมูล
ต้องการสอบถามเพิ่มเติม?
💬 ติดต่อฝ่ายสนับสนุนทาง Discord