Company registration in progress. The data controller's legal name, registration number and registered address are shown below as [[LIKE THIS]] and will be filled in once registration completes. Everything else on this page — what we hold, why, for how long and how to have it deleted — is accurate today.

Privacy notice

We sell documents, not attention. This page says exactly what we hold about you, why we are allowed to hold it, how long it stays, and how to make it go away. It is written to the GDPR because we sell to buyers in the EU, and the same rights are offered to everyone else. And because MeerLock is a data controller in Thailand, it also follows Thailand's Personal Data Protection Act B.E. 2562 (PDPA): see "Thai law (PDPA)" below.

No cookies, and no advertising or social tracking. This site sets no cookies of any kind and loads no advertising or social scripts. It does count page views and clicks, with Umami, which is cookieless: it stores nothing in your browser, and we do not use it to find out who you are. The other third party your browser contacts is Google Fonts, for the typefaces. One thing is different when you write to us: a form you submit carries the page you arrived on, the pages you read in that visit and the language of the page, so we can see where an enquiry came from and answer in your language. All of it is spelled out below, under "If you send a form or an email" and "What the website itself collects".

Who is responsible

The data controller is [[LEGAL ENTITY NAME]], registered under number [[REGISTRATION NUMBER]] at [[REGISTERED ADDRESS]], trading as MeerLock. For anything on this page — a question, a request, a complaint — write to contact@meerlock.com. A person reads it.

What we hold, and why

If you buy something

Your email address, the organisation name you gave, the name, billing country and business tax number Stripe collected, what you bought, the amount, the version of the terms of sale and licence you accepted and when that acceptance was recorded, the language of the page you ordered on (which records which language version of the terms was linked where you accepted them), and the Stripe identifiers for the payment. Legal basis: performance of the contract (Art. 6(1)(b)) or, where your organisation, not you, is the party, legitimate interests in performing our contract with it (Art. 6(1)(f)) for delivering and supporting your order, legal obligation (Art. 6(1)(c)) for keeping the tax evidence, and legitimate interests (Art. 6(1)(f)) for keeping the record of which version of the terms you accepted, when that was recorded and which language version was linked — the evidence of what we agreed, if it is ever disputed. We never see or store your card number — Stripe handles payment end to end. The emails our system sends you about your order are written in the language of the page you ordered on. We also give that language to Stripe: it sets the language of Stripe's payment page, and we save it on your customer record at Stripe as your preferred language, which Stripe uses from then on for the receipts, invoices and Customer Portal it shows you. We also use your billing country and business tax number to apply sections 6 and 7 of the terms of sale and licence (performance of the contract, Art. 6(1)(b), or legitimate interests in performing our contract with your organisation, Art. 6(1)(f), where your organisation is the party): to check that an organisation based in Thailand has paid in Thai baht, and to apply section 7 to your billing country — holding delivery until you give us the number where section 7 requires one, or not delivering where section 7 says we do not currently sell. Wherever section 7 provides for a refund, we refund the order in full.

When you download a file

The name of the file, the first and most recent time a download link was issued for it, and how many times. Legal basis: legitimate interests (Art. 6(1)(f)) — it is the evidence behind the refund rule in the terms, and it is what lets us answer "did my download work?". It is a count and two dates per file, not a browsing history. Separately, when the file itself is fetched, our cloud provider's audit log records that request: the time, the file (its storage path contains your order id), and the IP address and browser (user agent) it came from. It is the evidence that the file was actually fetched, should a payment ever be disputed, for example with your card issuer; a refund question under the terms is still answered from the download records above and from nothing else (legitimate interests, Art. 6(1)(f)). The log is signed so that any later change can be detected, so single entries are not removed from it; each is deleted automatically 365 days after it is written.

When you sign in to the portal

Your email address, to send the one-time sign-in link, plus short-lived counters, keyed on a one-way hash of your email address and of your IP address, that limit how many links can be requested. The request also carries the language of the page you asked from, so that the email and the link are in that language; it is used only for that email and is not kept. If an older page does not say, we use the language of your latest order. Legal basis: performance of the contract (Art. 6(1)(b)) or, where your organisation, not you, is the party, legitimate interests in performing our contract with it (Art. 6(1)(f)), and legitimate interests for the rate limit (stopping someone using our mail server to bother you). The sign-in link itself is a signed token that is never stored anywhere — it is verified by its signature, so there is no token database to leak.

If you send a form or an email

Whatever you write: name, email, company, the message, and for the three lists described below the fact that you asked us to write to you. The form also sends the language of the page it is on, so that we answer you — and send any sample you asked for — in that language; it is shown with your enquiry in our mailbox and our CRM, and kept and deleted with it. Our notification of your enquiry also records when it arrived and the IP address and browser (user agent) it came from, so that we can recognise abuse; they are kept and deleted with the enquiry. Legal basis: legitimate interests in answering you and in recognising abuse, and consent (Art. 6(1)(a)) for the three lists below, which you can withdraw at any time, as described below.

The lists you ask us to write to. There are three, and each is separate: joining one does not put you on another, and on the strength of a list we send you nothing beyond what that list says.

For all three we keep your email address, the language of the page and what the form sends as described above; a sign-up reaches our mailbox and our CRM like any other enquiry. Legal basis: consent (Art. 6(1)(a), and section 19 of the PDPA), which you give when you send the form. To leave a list: reply "remove me" to any of our emails, or write to contact@meerlock.com, and we take you off it. How long: each sign-up is kept for at most 24 months from the day you joined, on the same cycle as form messages, and ends sooner when you leave the list or ask for deletion, or once we have sent the one email the waitlist or "Tell me when it opens" promised. If the training product launches, or online purchase opens, after those 24 months, we will not write to you about it; you can sign up again at any time.

Plus where the enquiry came from. A form you submit also sends, and your record in our CRM then shows: the page you landed on, the site that linked you here (its address and path, never its search terms), any campaign parameters in the link you followed (the utm_source family), and the names of the pages you read in that visit — at most eight, and only from a fixed list of this site's own page names, never a free-text history and never anything from another website. We use it to answer you in context and to see which pages actually bring enquiries. It is information about pages until you press Send; once it is attached to your name it is your personal data like the rest of the enquiry, kept as long as the enquiry and deleted with it. Legal basis: legitimate interests. It lives in one entry in your browser's session storage, which your browser discards when you close the tab — so it never spans two visits — and if you would rather it were not attached to an enquiry, write to contact@meerlock.com instead of using a form (the page you landed on, the referring site and any campaign parameters are still counted, without your name, by the analytics described below).

What the website itself collects

Counts, not names. The pages load Umami, a cookieless analytics service, which records that a page was viewed and that certain things were clicked — a pack card, the pack picker, the order panel, a currency switch, the start of a checkout, a completed payment, a form being sent, a sign-in request, a file download (with the file's name) and how far down the homepage you scrolled — with the currency a price was shown in where there is one, and, for the first page of a visit, the page you landed on and any campaign parameters in the link you followed. With every page it also receives the page's full address, including anything after the '?' such as campaign parameters or an advertiser's click identifier. With each of these it receives the referring site, the browser, operating system, device type, screen size and language setting your browser reports, and works out the country, region and city from your IP address: your browser contacts Umami directly, so Umami sees your IP address and user agent, and by its own account keeps the page views and events, not the address. It sets no cookie and stores nothing in your browser. Umami itself groups the page views that come from the same IP address and browser within a calendar month into one session with no name attached, which its dashboard can list with the pages viewed; we do not try to match a session to a person. We use it to see which pages do their job and where people give up. Legal basis: legitimate interests (Art. 6(1)(f)) — measuring how our own pages are used, not who uses them. Nothing you type is ever sent to it: no email address, no message, no company name, no order number, no sign-in link.

Three things are kept in your browser, all by the pages themselves and none of them a cookie: the currency you pick in the header (one entry in local storage, so your prices are still right on the next page and when you come back), the language you pick in the header (one entry in local storage — we use it to offer you the other language, never to send you there automatically, so a link someone shares with you always opens in the language it was written in) and, for the length of one tab session, where you arrived and which of our pages you have read (one entry in session storage — the enquiry attribution described just above; the same entry also notes that the one "how far down the homepage did you scroll" count has already been sent, so we do not count it twice). The currency and language entries themselves are never sent anywhere. What does leave your browser is the currency or language of something you do: an order carries the currency it is charged in and the language of the page it was placed on; a "Tell me when it opens" sign-up carries the currency its total was shown in; a sign-in request, a form, and the account page when it lists your purchases carry the language of their page, so that what comes back to you is in it; and the analytics counts described above record which currency a price was shown in, alongside your browser's own language setting and — because the Thai pages are pages of their own — which language each page read was in. The visit entry leaves your browser with a form you submit, and its first page, referring site and campaign parameters also reach those analytics counts, with no name attached; your browser discards it when you close the tab. Clearing your browser data removes all three.

The currency you are shown first. Until you pick a currency yourself, the page chooses one from the country you appear to be in: our hosting (Amazon CloudFront) reads that country from your IP address and passes only the two-letter country code to the page, and failing that the page uses your device's time zone or your browser's language setting. This happens in your browser; the country is not stored or sent anywhere, and only the currency you end up being shown reaches the analytics counts described above and, if you use it, a "Tell me when it opens" sign-up. Legal basis: legitimate interests (Art. 6(1)(f)).

Our backend writes a log line for each request containing the route, the status, the timing and — for a checkout, a payment, a form or a download — the order id or CRM record id, with the few details needed to trace a fault (such as what was chosen and its currency, the language set at Stripe, the billing country of an order held or not delivered under section 7 of the terms, which form was sent, the file name and how many times it was fetched); email addresses, message contents and sign-in tokens are deliberately kept out of the logs, and that is enforced by an automated test rather than by good intentions.

The pages load their typefaces from Google Fonts (Inter and Poppins on every page, Caveat on the homepage too, and Prompt and Noto Sans Thai on the Thai pages and the page-not-found page), so your browser requests them from Google's servers and Google therefore sees your IP address and user agent, as it would for any site using that service. We embed no other third-party resource. Legal basis: legitimate interests (Art. 6(1)(f)).

How long we keep it

WhatHow longWhy, and how it ends
Order records, and the copy of each in our CRM (email, name, company, country, tax number, amounts, Stripe ids, the terms version you accepted and when that was recorded, the language of the order; the CRM copy has no terms record but shows your downloads)10 yearsTax evidence: EU OSS record-keeping runs to 10 years and Thailand's to 5, and keeping one period is simpler than keeping two. The terms record and the language of the order belong to the order and end with it. On request we delete everything except what tax law requires us to keep and the record of the terms you accepted (see below); the CRM copy goes on request.
Download records (file, first and last request, count)With the orderThey are part of the order record and are what a refund question is answered from.
Your personalised copies of the documents, labelled with your organisation's name (if you gave no organisation name when ordering, the label shows the name entered at checkout or, failing that, the order's email address instead)90 days after they are madeDeleted automatically by a storage lifecycle rule. Nothing is lost: a fresh copy is made from the master the next time you download. Less of your data sits at rest.
Sign-in links (magic-link tokens)Never storedThey are signed, not saved. They stop working 15 minutes after they are issued.
Sign-in, sample and form rate-limit counters (hashed email and IP address)About 2 hoursDeleted automatically by the database's own expiry.
Server logs30 daysDeleted automatically by the log service's retention setting.
Download audit log (time, file, IP address and browser of each file fetch)365 daysDeleted automatically by a storage lifecycle rule. It is signed so that a later edit is detectable, so it is not edited to remove one person before then.
Form and enquiry messages and sign-ups to the three lists, including where the enquiry came from, the language of the page, and the IP address and browser it was sent from; and the notices that reach our mailbox about orders held or not delivered under section 7 of the terms, or that an email we sent you bounced or was reported as spam24 monthsThey arrive in our mailbox, and enquiries also in our CRM; we clear them out on that cycle, or sooner if you ask. The attribution goes with them — it is part of the enquiry record, not a separate one. A sign-up to a list ends sooner when you leave the list and, for the waitlist and "Tell me when it opens", once that list's one email has been sent.
Where you arrived and which pages you have read (in your browser)One tab sessionOne session-storage entry. Your browser deletes it when you close the tab; it never spans two visits. It is attached to an enquiry only if you submit a form, and then it is kept with the enquiry above. Its first page, referring site and campaign parameters are also counted by the analytics below, without your name, and kept as those counts are.
Page-view and click counts (Umami)6 monthsThe retention of the plan we use; older data is dropped by Umami. They contain no cookie, no name and nothing you typed. Umami groups them into sessions worked out from IP address and browser, so a session in them may relate to your visit; if you ask us to delete it, we reset the analytics data from the Umami dashboard, which we can do at any time.

Who processes it for us

We use five processors, and no others. None of them is paid with your data, and each processes it only on our instructions — except that Stripe also uses payment data for its own purposes as a controller, such as fraud prevention and the legal obligations that apply to it, under Stripe's own privacy policy.

ProcessorWhat it handlesWhere
StripePayment, card data, invoices and receipts, your email and company name, the billing address and tax number you enter at checkout, the terms version you accepted and the language you ordered inIreland / United States
Amazon Web ServicesOur backend, the order database, the document storage, the server logs, the download audit log, and serving these web pages (Amazon CloudFront)Singapore (ap-southeast-1); the web pages are served from a CloudFront location near you
Amazon SESSending the delivery emails, the emails about orders held or not delivered under section 7 of the terms, sign-in links, requested samples and enquiry notifications. Bounces and spam complaints about these emails are forwarded to our mailbox, so that we know when an email did not reach you (legitimate interests, Art. 6(1)(f)).Singapore (ap-southeast-1)
Zoho CRM and Zoho MailThe customer and order record we keep to support you, and — for an enquiry — where it came from; both show the language you used. Zoho also hosts our mailbox, where enquiry notifications, our notices of orders held or not delivered under section 7 of the terms, the bounce and spam-complaint notices, and the emails you send us arriveUnited States (Zoho's US data centre)
UmamiCookieless page-view and click counts, grouped into sessions that carry no name. No cookie, nothing you type: it never receives your email address, your message or your orderUmami Cloud, a hosted service that stores its data in the European Union. Your browser contacts it directly, so — as with Google Fonts — it sees your IP address and user agent with each page view; Umami uses them to work out the country, region, city, browser and device and, by its own account, keeps the page views and events, not the address

Transfers outside the EEA. MeerLock operates from Thailand and its infrastructure runs in Singapore, so your data leaves the EEA. Transfers rely on the standard contractual clauses in each provider's data-processing agreement. What is transferred is an order record with its download records and the download audit log, or an enquiry or sign-up you sent. Umami stores its data in the European Union; what leaves the EEA from it is the page views and events we read in its dashboard from Thailand, not the address.

Your rights

You can ask us to: show you what we hold (access), correct it, delete it, hand it over in a portable format you can use with another system (portability), restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on consent you can withdraw it at any time.

To ask for deletion: email contact@meerlock.com from the address on the order, or tell us which address to look up. We will delete your portal access, your download records, your personalised copies, your CRM record and any enquiry correspondence. Entries in the signed download audit log are not removed one by one; they are deleted automatically 365 days after they are written. What we must keep is the order record itself — the invoice, amount, country and tax number — for as long as tax law requires it; that is a legal obligation, not a choice. For the same period we also keep the record of which version of the terms of sale and licence you accepted, when that was recorded and which language version was linked, because it is the evidence of what we agreed if either of us ever needs it. Stripe keeps its own record of the payment, including the details it collected at checkout and the terms version and language we attached to it, for as long as the law requires it to. We keep nothing beyond these. We act on your request without delay and no later than 30 days after we receive it.

If you think we have handled your data badly, please tell us first — but you also have the right to complain to your data protection supervisory authority.

Thai law (PDPA)

MeerLock is a data controller in Thailand under the Personal Data Protection Act B.E. 2562 (PDPA) — the same controller named under "Who is responsible" above. Everything this page describes applies to you wherever you are; this section sets out what Thai law adds.

The legal bases under the PDPA for each purpose described above:

What you must give us. To buy, you must give your email address and what Stripe's checkout asks for, including the billing address and, for many countries, a business tax number; without them the order cannot be completed, and where section 7 of the terms requires the tax number we hold delivery until we have it. On a form we need your email address (and, on an enquiry form, your name) to answer you; without it the form cannot be sent. Everything else is optional, and joining a list is never a condition of buying or of an answer.

Your rights as the data subject. Under the PDPA you have the right to access your personal data and obtain a copy of it, or to ask us to disclose how we obtained personal data about you that you did not consent to; to receive it in a format you can use with another system and have it sent or transferred (portability); to object to its collection, use or disclosure; to have it erased or destroyed, or made anonymous; to have its use restricted; to have it rectified so that it is accurate, up to date, complete and not misleading; and to withdraw your consent. The scope of and exceptions to each right are as the PDPA sets them — for example the order record that tax law requires us to keep, as described under "Your rights".

How to exercise them: email contact@meerlock.com, or write to our registered address, [[REGISTERED ADDRESS]], saying which right you are exercising and which email address we should look up. We act on your request without delay and no later than 30 days after we receive it; if we refuse any part of it, we tell you why within the same period.

Complaints: please tell us first — but you have the right to complain to Thailand's Office of the Personal Data Protection Committee (PDPC), at www.pdpc.or.th.

Transfers outside Thailand. Every processor named under "Who processes it for us" is outside Thailand — in Singapore (Amazon Web Services and Amazon SES), Ireland and the United States (Stripe), the United States (Zoho) and the European Union (Umami) — so your data is sent or transferred to them as that section describes. All these transfers rely on appropriate safeguards under section 29, paragraph 3, of the PDPA, set out in each provider's data-processing agreement; where you are yourself the party to the contract, a transfer needed to perform it for your order is also permitted by the exception in section 28(3) of the PDPA. Your browser also sends your IP address and user agent directly to Google (Google Fonts), as described under "What the website itself collects". Beyond the processors above, we disclose personal data only where the law requires it (for example to the Revenue Department, our auditor or a court), to our accountant or lawyer, who are bound by confidentiality, when we need their advice on a tax, accounting or legal matter that concerns you, and, if a payment is disputed, the evidence described above to Stripe and your card issuer.

Children

This is a business product. It is not intended for anyone under 16 and we do not knowingly collect their data. If you are a minor under Thai law (under 20), please do not join any of the lists without the consent of the person with parental authority.

Changes

If this notice changes, the version and date below change with it. Anything that materially affects an existing customer will also be emailed.

Language

This notice is made in Thai and in English, with the same content. The Thai version is the original, and the English version is a complete translation of it, true to the meaning of the Thai. Both carry the same version number and date, and we will not change either one without changing the other to match. If you find that the two say different things, please tell us at contact@meerlock.com: we will correct them to match, and in the meantime we will follow whichever version gives you more protection or more rights.

Version 1.3 — 25 September 2026. Related: the terms of sale and licence.