Extra International (Thailand) Co., Ltd. takes the protection of your personal data seriously. This policy explains how we collect, use, disclose and retain your personal data when you use our website and services, in accordance with the Personal Data Protection Act B.E. 2562 (2019).
Seller and registered company
The website and online store operating under the CiNO Coffee brand are operated by the following legal entity.
- Registered company
- Extra International (Thailand) Co., Ltd.
- Taxpayer identification number
- 0125567004752
- Registered address
- 25/5 Moo 4, Bang Mae Nang Sub-district, Bang Yai District, Nonthaburi 11140, Thailand
- [email protected]
- Telephone
- 094-912-5511
- Trading name
- CiNO Coffee is a trading name of Extra International (Thailand) Co., Ltd. Your counterparty in any purchase is the legal entity named above.
The name and address shown above are the entity's registered particulars filed with the Department of Business Development. The English pages show the English-language form of the same entity.
The company is VAT-registered (Phor.Phor.20) under the taxpayer identification number shown above, which is also its juristic-person registration number. Retail prices displayed on this website are therefore inclusive of 7% VAT, and the company issues tax invoices in accordance with Revenue Department requirements. As regards electronic commercial registration, juristic persons are exempt under the Ministry of Commerce Notification on Commercial Activities Requiring Registration B.E. 2567, effective 5 June 2024, because a juristic person's particulars are already held in the Department of Business Development's business registry. Sales offered through this website constitute direct marketing under the Direct Sales and Direct Marketing Act B.E. 2545; your rights under that Act are set out in the Cancellation, Return and Refund Policy.
Data controller
The data controller under this policy is Extra International (Thailand) Co., Ltd., taxpayer identification number 0125567004752, registered office at 25/5 Moo 4, Bang Mae Nang Sub-district, Bang Yai District, Nonthaburi 11140, Thailand.
You may contact us about personal data matters at [email protected] or by telephone on 094-912-5511.
The company has assessed that it is not required to appoint a Data Protection Officer under section 41 of the Personal Data Protection Act B.E. 2562. It is not a state agency; its core activity is not the regular and large-scale monitoring of personal data; and its core activity is not the large-scale collection, use or disclosure of sensitive personal data under section 26. The company nonetheless remains subject to every other duty under that Act, and you may contact us about personal data through the channels in clause 12.
Personal data we collect
- Account dataThe email address or Thai mobile number you sign up with — you provide one of the two, and it becomes the identifier you sign in with — together with your password, which is stored only in a one-way hashed form. We send a verification code to that email address or mobile number when you sign up, when you reset a forgotten password, and when you change the email address or number on your account.
- Profile dataYour name, telephone number, date of birth, preferred language and brewing preferences. All of these are provided voluntarily, except where the telephone number is the identifier you sign in with, in which case it is the account data described above.
- Address book dataRecipient name, recipient telephone number, address lines, sub-district, district, province and postal code.
- Order dataWhen you place an order we record the contact name, email address, telephone number and delivery address against that order, including where you order without registering an account.
- Technical dataWe record the IP address of the device requesting a verification code, whether that code is sent by SMS or by email, in order to apply rate limits and prevent abuse. We may also record browser or device information alongside your active sessions so that you can review them and sign out of another device.
- Business enquiry dataIf you complete our business contact form we collect your contact name, email address, telephone number, company name and the message you send us.
- Business account applicationCompany name, business type, taxpayer identification number, expected order volume, contact name and telephone number, together with the registration document you upload, such as a Por Por 20 form or a company affidavit.
- Tax document dataIf you request a tax invoice we store the name, address and taxpayer identification number you supply. Where a refund is made by bank transfer we store the bank account number you provide for that refund.
- Consent recordsWhen you accept our Terms of Service and this Privacy Policy and declare that you are 18 or over, we record which version of each document you accepted, the date and time, the language you read it in, and whether you accepted at registration or when placing an order. Where you accept while ordering without an account, the record is kept against that order. We do not record your IP address or your browser details alongside it.
This service is intended for persons aged 18 or over. The company does not knowingly collect personal data from anyone under 18, and if we learn that we have done so inadvertently we will delete it without delay. As for the birthday you may enter voluntarily on your profile page, we keep it solely in order to offer you a benefit during your birthday month; it is not used to verify your age, and you may leave it blank or remove it at any time without affecting your orders or the service you receive.
We never store your credit or debit card number in our systems under any circumstances. Card details are transmitted to and held by our payment service provider directly; our systems retain only a payment reference.
Purposes and lawful bases for processing
- Performance of contractAccepting orders, taking payment, delivering goods, notifying you of order status and providing after-sales support. The lawful basis is necessity for performance of a contract.
- Legal complianceIssuing tax invoices and credit notes, and retaining accounting and tax records for the periods the law requires. The lawful basis is compliance with a legal obligation.
- Legitimate interestsMaintaining the security of our systems, preventing fraud, and limiting the number of verification code requests to prevent abuse.
- MarketingNewsletters or promotional offers — we act only where you have given consent. You may withdraw consent at any time from the communication preferences page in your account, without affecting your ability to place orders or receive service under our contract.
- Consent to this policyWhen you create an account or place an order we ask you to accept this policy, and that acceptance is recorded as your consent, together with the version you accepted. It sits alongside the bases above rather than replacing them: where the law requires us to keep a record, or where we must process your data to perform our contract with you, that duty continues. Withdrawing the marketing consent described below never affects your orders or the service you receive.
Some of the data described above is genuinely optional and some is not, so it is worth stating what follows if you do not provide it. Without a contact name, email address, telephone number and delivery address we cannot accept or deliver an order, because those are the details the order record and the carrier depend on. Without the name, address and taxpayer identification number a tax invoice requires, we cannot issue one. Without a bank account number we cannot pay a refund that is not being returned to a card. An email address or a Thai mobile number is required to hold an account, because one of the two serves as the identifier you sign in with. By contrast, the profile details described in section 2 as voluntary, such as date of birth and brewing preferences, carry no such consequence, and marketing consent may be withheld or withdrawn without affecting your orders or the service you receive.
Cookies
Our website currently uses only three cookies, all strictly necessary for the service to function: a cookie holding your signed-in session, a cookie protecting against cross-site request forgery, and a cookie identifying your shopping basket before you sign in.
We do not set analytics, advertising or cross-site tracking cookies, and we do not embed third-party tracking tools on the website. Should this change in future, we will update this policy and seek consent where the law requires it.
Disclosure to service providers
We disclose your personal data only as necessary to service providers who process it on our behalf under contract. We do not sell or rent your personal data to third parties for marketing purposes under any circumstances.
- ResendEmail delivery provider, used to send order confirmations, identity verification emails, verification codes and business application outcome notices. Receives your email address and name.
- SMSMKTSMS delivery provider, used to send verification codes. Receives your mobile number, and generates and checks the code itself.
- CloudflareNetwork and security provider. Acts as the intermediary carrying traffic between your browser and our systems, and filters malicious access.
- StripePayment provider. Receives the information needed to process a transaction when you pay by credit card, debit card or PromptPay. Your card details go directly to that provider and are not stored in our systems.
- ShippopShipping aggregator and the carriers in its network. Receive the recipient's name, telephone number and delivery address in order to deliver your goods and issue a tracking number.
Documents you upload during a business account application are stored on our own server and are not entrusted to an external file storage provider.
Cross-border transfer of data
Our systems and databases are hosted on servers located in Asia, in Jakarta, Indonesia. Your personal data is therefore stored and processed outside the Kingdom of Thailand.
In addition, some of the service providers listed in section 5 may process data outside Thailand.
Transfers abroad under this clause are made to processors acting on the company's instructions and therefore fall under section 29 of the Personal Data Protection Act B.E. 2562. The company requires each such provider to be bound by a Data Processing Agreement and selects providers that maintain internationally recognised security measures. These transfers are necessary to perform our contract with you — for example, sending order confirmation emails and accepting payment — so we do not seek separate consent for the transfer itself.
Security measures
Your password is stored using a one-way hash produced by the argon2id algorithm. We cannot read your password, and no member of staff has access to it.
Verification codes sent by email, two-factor recovery codes, email verification tokens and session refresh tokens are stored only as hashed values, never in a form that can be replayed. A verification code sent by SMS is generated and checked by our SMS provider, so we hold no copy of it at all.
The taxpayer identification number you supply for a tax invoice, and the bank account number you supply to receive a refund, are encrypted in our database using AES-256-GCM and are never echoed back for display or written to system logs.
The field-level encryption described above applies to those two items and to the staff authenticator secret described below. Other data, such as your email address, telephone number, address, date of birth and the taxpayer identification number supplied during a business account application, is stored in the database without per-field encryption, though subject to role-based access controls. All traffic between your browser and our systems is encrypted in transit using HTTPS.
Staff access to data is restricted according to role, and every staff member must complete two-factor authentication with an authenticator app before accessing our back-office systems. The secret that app is set up with is stored encrypted using AES-256-GCM, in the same way as the items described above.
Data retention
Accounting and tax records, such as tax invoices and credit notes together with the related order data, are retained for the periods required by tax law and cannot be deleted on request during those periods.
| Category | Retention |
|---|---|
| Account data | Membership + 5 years |
| Customer data | 5 years after relationship ends |
| Business enquiry (lead) data | 2 years from last contact |
| Order documents and tax invoices | 5 years |
| Payment transaction records | 10 years |
| System access logs and IP addresses | 180 days |
| Security logs | 1 year |
| Audit logs | 5 years |
| Backups | Rolling cycle |
| Consent records | 2 years beyond a request for erasure |
Once those periods expire and no legal ground requires further retention, we delete, destroy or anonymise the data. Data passed to the external providers listed in clause 5 is retained under those providers' own policies, which may be longer than the periods above for legal and anti-fraud reasons.
Your rights as a data subject
- Right of accessAccess your personal data and obtain a copy of it, and be informed how data you did not consent to provide was obtained.
- Right to rectificationHave your data corrected so that it is accurate, current and not misleading. You can do this yourself at any time from your account pages.
- Right to erasureRequest erasure or destruction of your data, or that it be anonymised, subject to our obligation to retain accounting and tax records under the law.
- Restriction and objectionRequest restriction of processing, and object to the collection, use or disclosure of your data in the cases the law provides.
- Right to portabilityReceive your data in a machine-readable format and have it transmitted to another data controller.
- Right to withdraw consentWithdraw any consent you have given at any time, without affecting the lawfulness of processing already carried out.
To exercise any of these rights, contact us at [email protected] or on 094-912-5511. We will consider your request and respond within the period the law prescribes. If you believe we have not complied with the law, you have the right to lodge a complaint with the Personal Data Protection Committee.
Deleting your account
You may request deletion of your account yourself from your account pages. When you confirm, your account is deactivated immediately, you are signed out of every device, and the account can no longer be used to sign in.
For 30 days from the date of your request you may restore the account from the account recovery page, using the email address or mobile number you signed up with together with your password. After 30 days the account can no longer be restored.
Please note that deleting your account does not delete orders already placed or tax documents already issued, as these are records we are required by law to retain. If you wish data to be erased or anonymised beyond this, please contact us so that we can consider your request individually under section 9.
Changes to this policy
We may update this policy from time to time. The date of the most recent update is shown at the top of this page. Where a change is material, we will notify you through an appropriate channel before it takes effect.
Contact
If you have questions or comments, or wish to exercise your rights under this policy, please contact Extra International (Thailand) Co., Ltd. at [email protected], on 094-912-5511, or at the registered address given above.