Privacy Policy
Last updated: June 29, 2026
KaoJai.ai, operated by OK Production Co., Ltd., respects your privacy and is committed to protecting your personal data. This policy covers our platform websites, including kaojai.ai, and authenticated product areas, including admin.kaojai.ai. It explains what information we collect, how we use it, with whom we may share it, and the safeguards we apply.
Information We Collect
- Information you provide directly, such as your name, email address, and any details you choose to share.
- Account and workspace information used to provide authenticated product areas, including user profile, tenant, role, settings, and integration status.
- Information collected automatically, including usage data, cookies, local or session storage, device and browser information, IP address, security logs, diagnostics, and log files.
- Analytics and product interaction data, such as pages viewed, buttons clicked, navigation paths, feature usage, errors, performance signals, and session-level activity.
- If you connect a third-party platform such as LINE, Facebook, Instagram, Shopee, Lazada, TikTok ("Connected Platforms"), we collect only the data and permissions you explicitly authorize from each platform.
- For marketplace integrations, authorized data may include product catalog details, product images, descriptions, prices, stock, order details, customer contact or delivery information, and customer messages, but only where needed for enabled features and approved platform permissions.
Cookies, Analytics, and Session Activity
We use cookies, local storage, session storage, logs, and analytics tools to operate, secure, debug, and improve KaoJai.ai. In authenticated product areas such as admin.kaojai.ai, these technologies are used for core service functions such as sign-in, session management, tenant selection, security, fraud prevention, preferences, and product analytics.
On public marketing pages, we may use privacy-preserving analytics to understand aggregate behavior and improve the site. Depending on visitor region and product configuration, we may also collect session activity such as clicks, scrolling, page navigation, and replay-style interaction data. Session activity is used for product debugging, conversion analysis, user experience improvement, and abuse prevention.
We configure analytics to reduce unnecessary personal data where practical, including masking page text and element attributes, avoiding person profiles for public marketing analytics, limiting persistence where appropriate, and stripping query strings from analytics page URLs. We do not intentionally collect passwords, payment card numbers, access tokens, or sensitive message contents through session replay tools.
Some tracking features may be disabled or limited for visitors from certain regions, including the EU, EEA, UK, and Switzerland. If a region cannot be determined reliably, we may apply the more privacy-restrictive configuration by default.
How We Use Information
We use collected information to:
- Operate, maintain, and improve KaoJai.ai.
- Communicate with you regarding services, updates, or support.
- Authenticate users, maintain sessions, remember preferences, and protect accounts and workspaces.
- Measure site and product usage, diagnose errors, investigate abuse, improve user experience, and prioritize product improvements.
- Comply with legal and regulatory obligations.
- Provide integrations you request with Connected Platforms, strictly within the access scope you authorize.
We do not sell your personal information.
We use connected platform data for the customer workspace and feature that requested it. We do not use customer order details, contact details, or messages for unrelated advertising, resale, or data brokerage.
Sharing and Disclosure
We may share your information only in the following circumstances:
- With service providers and subprocessors that help us operate KaoJai.ai (such as cloud hosting, analytics, and email providers).
- With Connected Platform services, but only as authorized by you when you connect your accounts.
- As required by law, regulation, or valid legal process.
We do not share user data received from Connected Platforms with any third parties for marketing or advertising purposes.
We do not allow analytics or session activity providers to use connected platform data for their own advertising or data brokerage purposes.
Data Protection and Security
We apply reasonable administrative, technical, and organizational safeguards to protect personal data and connected platform data, including:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Restricted access controls, ensuring only authorized staff can access sensitive data.
- Regular monitoring and auditing of our systems for vulnerabilities.
Sensitive user data from Connected Platforms, such as access tokens, is stored securely, used only to provide KaoJai.ai services, and never transferred to unauthorized parties.
Connected Platform Data
Our data protection controls apply to personal data, customer conversation data, business content, access tokens, profile identifiers, and other data we receive from Connected Platforms. For Facebook and Instagram integrations, this includes data received through Meta APIs and permissions granted to our app.
When a business customer connects a platform account, the customer is confirming that they are authorized to connect that account and use the data in KaoJai.ai. We process connected platform data on the customer's instructions, subject to applicable law, platform rules, and the permissions approved for our app.
We collect and process connected platform data only to provide the services requested by the customer, including unified inbox, customer support workflows, AI-assisted replies, chatbot automation, marketplace operations, analytics, and account administration.
If a customer enables a content creation or publishing feature, we may use authorized product catalog data, product images, descriptions, prices, stock, and availability to create or publish content for that customer's business. We do not use customer personal data, order details, chat messages, or reviews for public content unless the customer gives clear instructions and has the legal right to do so.
- We request only permissions needed for the enabled feature.
- We do not sell personal data or connected platform data.
- We do not share connected platform data with third parties for advertising, marketing, data brokerage, or profiling.
- We do not use connected platform data to make eligibility decisions for employment, housing, credit, insurance, healthcare, education, or other restricted decision-making purposes.
- We may use authorized business data to operate, support, train, evaluate, and improve features and functionality for that customer's business, including product search, generate replies, summaries, retrieval, and workspace-specific configuration, content generation, automation, and AI-assisted workflows.
- AI features may process authorized data inside a customer workspace to draft replies, summarize conversations, retrieve product or policy context, automate workflows, and improve that customer's configured features.
Service Providers and Subprocessors
We may use service providers for cloud hosting, storage, analytics, email, security, and support operations. These providers may process data only to deliver services to KaoJai.ai, must keep data confidential, and must apply appropriate security safeguards. We do not permit service providers to use connected platform data for their own marketing or advertising purposes.
Retention and Deletion
We retain personal data and connected platform data only for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and enforce agreements. Customers can disconnect platform integrations at any time. When a customer disconnects a platform integration, we stop new collection from that platform and revoke or remove stored tokens where technically available. After a verified deletion request, we delete personal data from active systems within 30 days unless retention is legally required. Backup copies are removed on the normal backup lifecycle.
Analytics, diagnostic, security, and session activity data may be retained for shorter operational periods or aggregated over time. We may keep security logs when needed to investigate abuse, protect the service, or meet legal obligations.
Incident Response
If we identify unauthorized access, disclosure, alteration, or loss of personal data, we investigate promptly, contain the issue, remediate the cause, and notify affected customers, platforms, or regulators when required by applicable law or platform policy.
Your Rights
You have the right to access, correct, or delete your personal information. Depending on your location, you may also have rights to object to or restrict certain processing, request portability, withdraw consent where processing is based on consent, or complain to a data protection authority.
You may also revoke access to your Connected Platform accounts at any time through your account settings on the respective platforms.
For privacy questions or requests, contact OK Production Co., Ltd. at support@kaojai.ai.