Privacy Policy
This Privacy Policy (“Privacy Policy”) governs the collection, use, disclosure and protection of personal data of individuals provided to Lenskart Solutions (Thailand) Co., Ltd. (“the Company” or “We” or “Us” or “Ourselves”) through Our websites and online services, including ‘lenskart.com/en-th/’ and/or ‘lenskart.com/th-th’ (‘Website’) and our mobile applications (‘Application’) or Company’s retail stores (‘Stores’). This Privacy Policy is intended to provide clear and complete information about the personal data of individuals that the Company collects in connection with Company’s services on the Website or Application or Stores and the way such personal data is stored and used.
We are committed to protecting the privacy and personal information of individuals provided to Us by users of the Website, Application and/or at the Stores (“User” or “Users” or “You” or “Your”).
Acceptance of terms of the Privacy Policy by the Users:
This Privacy Policy is applicable on You when You access and use Our Website/ Application/Stores. By accessing and using the Website or Application and agreeing to this Privacy Policy or accessing and using Stores, You signify Your acceptance of the Privacy Policy and expressly consent to Our collection, use, disclosure, and retention of Your personal information as described in this Privacy Policy. If You do not agree to this Privacy Policy and/or to Our processing of Your data/information in the manner outlined in this Privacy Policy, please do not use this Website or Application or submit any personal information to Us. We reserve the right to modify or amend this Privacy Policy at any time and for any reason. However, We commit to ensuring that the privacy rights of individuals shall be maintained. In order to keep You informed, We shall notify Users of any material changes to Our Privacy Policy along with the effective date of such modification/alteration to the Privacy Policy on the homepage of the Website. We encourage you to look for updates and changes to Our Privacy Policy when you visit our Website or Application or Stores.
Scope of the Privacy Policy:
This Privacy Policy refers and applies only to the Website, Application, and Store. Its main aim is to inform the Users of the way their personal information is collected and processed, providing relevant information to the User, as well as fixing the accessing conditions and the use of the Website, Application, and Store.
Information collected:
For the purposes of this Privacy Policy, “Personal Data” shall have the same meaning as ascribed to it in the Personal Data Protection Act B.E. 2562 (2019) or notifications issued thereunder, with the Personal Data Protection Committee(“PDPA”). Personal Data means any information that may be used to identify an individual, including but not limited to the following:
(a) Information about Your personal identity inter alia as title, full name, age, gender, photograph, facial data such as pupillary distance and face width measurements, CCTV records, etc.
(b) Your contact details such as Your address, postal code, phone number and any other contact details You provided to Us;
(c) User ID information such as Your username, email address and other security-related information used by You in relation to access and use Our Website and its content, User ID of social networks, etc;
(d) Your financial details such as debit/credit card or bank information, credit/debit card number, credit card type, issuance/expiration date, cycle cut, account details, bank account details, prompt pay number payment details and records and any other financial details.
(e) Your sensitive data, such as facial recognition, person identity information (biometrics), face, information from the iris recognition, physical health or condition and medical history.
Some personal information we collect is sensitive information. Sensitive information includes health information including things like facial recognition, person identity information (biometrics), face, information from the iris recognition, medical history, prescriptions, retinal images and health conditions. We collect Sensitive Information in order to provide health services to you. Sensitive information will be used and disclosed only for the purpose for which it was provided, or a directly related secondary purpose, unless you agree otherwise, or where certain other limited circumstances apply (for example, where required by law or necessary for the protection of a person/persons).
We collect information from children, quasi-incompetent persons, and incompetent persons only with the required consent of a parent or legal guardian. If we become aware that we have collected data from individuals under the age of 20 without parental consent where it is required, nor from quasi-incompetent or incompetent persons without their legal guardian’s approval, we will promptly delete the data or ensure it is processed under a legal basis other than consent.
The aforementioned shall collectively be referred to as “Personal Data”. Personal Data will also include any personally identifiable information provided by You in any form during any interaction or communication with Us.
When You use Our Website or Application or Store, We collect and store Your Personal Information in order to record, support and facilitate Your participation in the activities You select, track Your preferences, to notify You of any updated information and new activities and other related functions offered by Us, keep You informed about Our latest, special offers, and other products and services available on/at the Website/Application/Store, to assist You with customer service or technical support issues, to follow up with You after Your visit to the Website/Application/Store. For the aforesaid purpose, We only collect such personal information that We consider relevant to understand You or Your interests. Personal Information may also get collected and shared with third-parties if there is content from/relating to the Website/ Application/Store that You specifically and knowingly upload, share or transmit to an email recipient, online community, or to the public, e.g. uploaded photos, posted reviews or comments, or information about You or anything posted by You that You choose to share with others through features which may be provided on Our Website. Such uploaded, shared or transmitted content will also be subject to the privacy policy of the online community, website, social media or other platforms to which You upload, share or transmit the content.
Apart from any Personal Data provided by You, We may also collect certain non-personal and/or technical information through third-party sources, platforms (such as social networking websites, databases, online marketing firms, and ad targeting firms) and other channels.
We may access information about You from third-party sources and platforms (such as social networking websites, databases, online marketing firms, and ad targeting firms), including:
1. Third-party social networking services (such as Facebook, X) regarding the Website/Application/Stores/Us, we may collect, personal contact information and/or any Personal Data that is part of Your profile on a third party social network (e.g. Facebook) and that You allow that third party social network to share with us (e.g. name, email address, gender, birthday, city, profile picture, user ID, friend list). You can learn more about the data that we may obtain about You by visiting the privacy policies on the website of the relevant third party social network.
2. Demographic data, such as age range, gender, and interests;
3. Advertisement interaction and viewing data, such as ad click-through rates and information about how many times You viewed a particular
4. unique identifiers, including mobile device identification numbers, that can identify the physical location at the point of access in accordance with applicable law.
Please note that the We may combine the information that we collect with information we obtain from third-party sources.
Sometimes this data can be shared with partners who help Us deliver ads to You on third party websites/entities not controlled by Us. The aforementioned information herein collected by Us under clause 3.1, 3.2 and 3.3 are collectively referred to as “Information”.
Where we are required by law to process Your Personal Data or need to process Your Personal Data under the terms of a contract We have with You (or take steps at Your request before entering into a contract) and You fail to provide Your Personal Data when requested, We may not be able to perform obligation under the contract We have with You or plan to enter into with You. In this case, We may have to decline to provide the relevant services, but We will notify You if this is the case.
We may use the Information for processing Your login for Our Website/ Application/ Store.
We use technical data such as Your IP address to help diagnose problems and resolve issues related to the functionality of the Website/ Application.
We aggregate and analyze the Information that We collect and may use the same to monitor and analyze use of Our services/Website/ Application/ Store, to increase Our Website/Application/Store's functionality, and to better tailor Our content and design to suit Our Users’/visitors' needs so as to provide them with a smooth, efficient, safe and customized experience while using Our Services/Website/ Application/Store.
We may also use the Information that We collect to fulfill Your requests for products, services, and information, which helps us respond to Your customer service requests and support needs, more efficiently. For example, We may use Your contact information to respond to Your customer service requests or to enable You to participate in features on the Website such as surveys, polls, sweepstakes, and message boards. We may also use information in the aggregate to understand how Our Users as a group use the services and resources provided on at Our Stores/Website/ Application and use feedback You provide to improve Our products and services.
Further, We use the Information to resolve disputes; troubleshoot problems; measure consumer interest in the services provided by Us, inform You about online and offline offers, products, services, and updates; customize Your experience; detect and protect Us against error, fraud and other criminal activity; enforce Our User Agreement, and in general to improve the Users experience.
We may use the Information that we collect to send You e-mail communications, such as editorial updates, information about Your account or changes to the Website, newsletters, marketing and promotional messages about Our own or Our marketing partners' products and services that may be of interest to You. It may also be used to respond to Your inquiries, questions, and/or other requests. If You signed up for one of Our email newsletters, we will also send You the newsletters that You requested. If You decide to opt-in to Our mailing list, You will receive emails that may include company news, updates, related product or service information, etc. If at any time the User would like to unsubscribe from receiving future emails, We include detailed unsubscribe instructions at the bottom of each email or User may contact us via Our Website.
We may use the information that we collect to comply with applicable laws, prevent illegal activities, to enforce the Privacy Policy, and to otherwise protect Our rights and the rights of Our Users. In addition to the uses identified above, we may use the Information that We collect for any other purposes disclosed to You at the time We collect Your information.
Disclosure of Information to Others:
We cooperate with law enforcement and regulatory inquiries, as well as other third parties to enforce laws, such as intellectual property rights, fraud and other rights, to help protect You and the community. Therefore, in response to a verified request by any statutory authority including but not limited to law enforcement agency or other government officials relating to a criminal investigation or alleged illegal activity, We may (and You authorize us to) disclose, as per the applicable laws, some of Your personal information as are reasonably necessary to respond/comply with the statutory mandate including but not limited to court orders or other legal process. We may access, use, transfer or disclose Your Personal Information to third parties such as government or law enforcement authorities or private parties if it is legally and statutorily required to do so under any of the following conditions:
- To satisfy any applicable law, rule, regulation, governmental requests or legal process.
- To protect and/or defend and/or enforce Our Privacy Policy for online services or other policies applicable to any online services in case of potential violations.
- To secure Our systems.
- To respond to claims that an advertisement, posting or other content violates the rights of a third party.
- To respond to claims that an advertisement, posting or other content violates the rights of a third party.
- To protect the rights, property or personal safety of the Users and the public in general for any reason..
- To detect, prevent or otherwise address fraud, security or technical issues.
- To prevent or stop activity we may consider to be or to pose a risk of being, an illegal, unethical, or legally actionable activity.
In case of any illegal, ethical or legally actionable activity, we may use IP address or other device identifiers, to identify users, and may do so in cooperation with third parties such as internet service providers, wireless service providers and/or law enforcement agencies, including disclosing such information to third parties, all in Our discretion. Such disclosures may be carried out without notice to You. However, we shall not sell, share or rent the Users Personal Information to any third party or use any users e-mail id for sending any unsolicited emails.
We share much of Our data, including Information about You, with Our parent, affiliates, subsidiaries, and joint ventures that are committed to serving Your online requests and related services, throughout the world. To the extent that these entities have access to Your personal information, they remain bound by the existing Privacy Policy. As We continue to develop Our business, we might sell or buy stores, subsidiaries or business units. In such transactions, Users’ Information generally is one of the transferred business assets but shall remain subject to the terms and conditions contained in this Privacy Policy.
We may employ third parties services to facilitate or outsource one or more aspects of the business, product and service operations that we provide to You through the Website/Application/Stores (e.g., search technology, customer service) and therefore We may provide some of Your personal information to these internal service providers. These internal service providers' are subject to the terms of this Privacy Policy and confidentiality agreements with Us and other legal restrictions that prohibit their use of Your personal information for any other purpose except to facilitate the specific outsourced service. In the event of Your direct involvement with the internal service provider, any additional information disclosed by You to them shall be subject to internal service provider’s own applicable privacy policy and the Company shall not be responsible for the same.
We do not sell or rent Users’ personal information to third parties for their marketing purposes, but with Your explicit consent, we may disclose Your personal information
- To third parties such as affiliates, services providers for the purposes for providing you with our services
- To third parties for their marketing and advertising purposes;
- To send You promotions, notifications, or other services. However, the Users have the right to opt-out of receiving marketing communications about the Company/Website/Store by sending us an email at dataprotectionofficer@lenskart.sg
We may transfer Your Personal Data to the countries outside of Thailand to Our parent and other affiliated companies and Our third party service providers as part of Our normal business operations to perform Our services. In case of international transfers originating from Thailand to another country, the transfer of Your Personal Data may take place where the Thailand Personal Data Protection Committee has recognised such country as providing an adequate level of data protection, Your Personal Data may be transferred on this basis. For transfers to countries not recognized by the Thailand Personal Data Protection Committee as having adequate data protection standards, We will implement appropriate safeguards, such as standard contractual clauses, to ensure Your Personal Data remains protected.
- (a) The purpose for which Your consent would be required. We use the Information to understand Your needs and accordingly facilitate Our services and route You through the relevant information that meets Your need. We do not sell, rent, trade or exchange any personally identifying information of Our Users. We may provide the Information to Our affiliates and service providers under contract (such as customer care, data analytics) to support the operation of the Website/Application/ Stores and Our services, which We cannot rely on other legal bases . To the extent we use Your personal information to market to You, we will provide You the ability to opt-out of such uses. We may also use the Information to provide contents and services that are targeted to Your interests. By accepting this Privacy Policy, You expressly agree to receive this communications/information. If You do not wish to receive these communications, You may opt out of the receipt of certain communications by sending an email at dataprotectionofficer@lenskart.sg specifying the communication/information You do not want to receive.
- The purposes we may rely on and other legal grounds for processing Your Personal Data We may also rely on
- (1) contractual basis, for our initiation or fulfilment of a contract with You;
- (2) legal obligation, for the fulfilment of the legal obligations;
- (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties
- (4) vital interest, for preventing or suppressing a danger to a person’s life, body, or health; and/or
- (5) public interest, for the performance of a task carried out in the public interest or for the exercising of official authorities.
We may collect, use, and disclose your Personal Data for the following purposes.
To enter into a contract and manage our contractual relationship with You; to support and perform other activities related to such services or products; to carry out financial transactions and services related to the payments, including transaction checks, verification, and cancellation; to process Your orders, deliveries, collections, and returns; to manage refunds and exchanges of products or services; and to provide updates on the delivery of products."
To protect the security and integrity of Our business; to exercise Our rights or protect Our interest where it is necessary and lawfully to do so, for example to detect, prevent, and respond to fraud claims, or violations of law; to manage and prevent loss of Our assets and property; to secure the compliance of our terms and conditions; to detect and prevent misconduct within Our premises which includes Our use of CCTV; to follow up on incidents; to prevent and report criminal offences and to protect the security and integrity of Our business.
Under the law, you are entitled to the following rights, subject to applicable exceptions:.
- a. Right to access information-You may have the right to access Your Personal Data which is in the Company’s possession or control.
- b. Right to erasure of personal data- You may have the right to request us to delete or erase Personal Data that We have collected about You.
- c. Right to withdraw consent- To the extent We are processing Your Personal Data based on consent, You may have the right to withdraw consent at any time, except as otherwise provided by law.
- d. Right to rectification -You may have the right to request Us to correct and rectify inaccurate Personal data.
- e. Right to restriction of processing – You may have the right to request that We limit the processing of Your Personal Data, under certain circumstances, such as when You contest the accuracy of the data or object to the processing.
- f. Right to data portability –You may have the right to receive Your Personal Data in a structured, commonly used, and electronic format, and to transmit that data to another controller, where technically feasible and applicable.
- g. Right to object -You may have the right to object to the processing of Your Personal Data where the processing is based on our legitimate interests or for direct marketing purposes.
We work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) software during the part where you enter your credit card or net banking details, which encrypts information You input. We constantly re-evaluate our privacy and security policies and adapt them as necessary to deal with new challenges. We do not and will not sell or rent Your personal information to anyone, for any reason, at any time, unless it is in (i) in response to a valid legal request by a law enforcement officer or government agency or (ii) where You have given Your consent, or (iii) utilize the same for some statistical or other representation without disclosing personal data. The information collected from You will be stored on the Company’s secured server and systems.
The Company maintains secure and reasonable security practices and procedures which are proprietary and unique to the Company (“Security Practice”). Such Security Practice involves measures such as but not limited to password protection, limitation of access to specified personnel on a need to know basis, and security measures including encryption if required and other physical security measures to guard against unauthorized access to the server and systems and information residing on such server and systems. The Company’s Security Practice protects against unauthorized access to, or unauthorized alteration, disclosure or destruction of the information. The Company’s Security Practice contains managerial, technical, operational and physical security control measures which are commensurate with the information assets being protected and with the nature of business. You acknowledge and agree that the Security Practice and procedures as mentioned above are reasonable and are designed to protect the information provided by You. We only reveal those numbers of Your account as required to enable us to access and provide You the required services relating to Your accounts. We make every effort to allow You to retain the anonymity of Your personal identity and You are free to choose a Login ID email address and password that keeps Your personal identity anonymous. Access to Your Registration Information and Your personal financial data is strictly restricted to those of our Company employees and contractors, strictly on a need to know basis, in order to operate, develop or improve the Service. These employees or contractors may be subject to discipline, including termination and criminal prosecution, if they fail to meet these obligations. With the exception of a Login ID in the form of an email address, which may be provided on an anonymous basis, and Your Third Party Account Information, which is required for providing the services, the Company does not require any information from You that might constitute personally identifiable information. It is important for You to protect against unauthorized access to Your password and to Your computer. Be sure to sign off when finished using a shared computer. As described in this Privacy Policy and with Your consent, the Company will from time to time connect electronically to Your online bank, credit card and other online financial accounts to process Your Order. Company will also use other third parties like courier companies to deliver products that you order on our website, to your delivery address.
Unless specified otherwise in this Privacy Policy, we will retain Your Information as long as permitted or required by applicable law. In some cases, even after cancellation of the user account, Your Information may be retained for the purpose of legal and regulatory compliances, resolving disputes, concluding activities related to account cancellation, enforcing Our agreements, Privacy Policy or for any other reason which may be deemed necessary under law. In accordance with the general statute of limitations under Thai law, your information may be retained for up to 10 years after the end of the contractual relationship. However, the information of the User will get anonymized upon cancellation of user account except for the abovementioned purposes.
You are responsible for maintaining the accuracy of the Personal Information submitted to Us at the time of login. If there are any changes in Your Personal Information details, please contact us at +66828919666or by e-mail at dataprotectionofficer@lenskart.sg to correct or update the information.
You agree and undertake to indemnify and hold harmless Us, from and against any and all suit, dispute, actions, damages, costs and expenses, if any, of whatsoever nature, arising out of or in any way connected with this Privacy Policy, Information and/or Your use or access of the Website/Application/Stores.
You expressly understand that under no circumstances, including, but not limited to, negligence, shall We be liable to You or any other person or entity for any direct, indirect, incidental, special, or consequential damages, including, but not limited to damages for loss of profits, goodwill, use, data or other intangible losses, resulting from circumstances, including but not limited to:
- Unauthorized access to or alteration of Information.
- Any unauthorized access to or use of Our secure servers and/or any and all Information stored therein.
You represent that You have accessed the Website/Application/Stores and have provided Information on Your own initiative and are responsible for compliance with all applicable laws. This Privacy Policy is governed by the laws of Thailand and the courts at Thailand shall have exclusive jurisdiction.
If You believe that information we hold about You is incorrect or out of date, or if You have concerns or further queries about how We are handling Your Personal Information or any problem or complaint about such matters, please contact our Data Protection Officer.
Below mentioned employee of Lenskart Solutions Limited (formerly known as Lenskart Solutions Private Limited) (the parent company of Lenskart Solutions (Thailand) Co., Ltd.) is designated under section 41 of the Personal Data Protection Act , B.E.2562 (2019) to be responsible for ensuring compliance with the PDPA (e.g., Data Protection Officer)
Data Protection Officer details:
Name: Mr. Vikram Gaur
Designation: Data Protection Officer
Contact email:dataprotectionofficer@lenskart.sg
Company details:
Lenskart Solutions (Thailand) Co., Ltd. No.944 Mitrtown Office Tower, 25th Floor, Unit no. S25018-S25019, Rama 4 Road, Wangmai Subdistrict, Pathumwan District, Bangkok 10330
You may give, manage, review or withdraw Your consent and also exercise Your other privacy rights under law by emailing the Data Protection Officer at the above email address. Data Protection Officer shall respond to any grievances or requests, as the case may be, within the timelines prescribed under the law.