CFmanager ("we," "our," or "us"), operated by Kanokphan Phathai Limited Partnership (ห้างหุ้นส่วนจำกัด กนกพรรณผ้าไทย), is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our application and connect with Meta Platforms (Facebook).
1. Information We Collect via Meta APIs
When you connect your Facebook Page to our application, we request specific permissions through the Meta Graph API to enable our core features. We only collect the minimum required data ("Platform Data") necessary for the functionality of our services, which includes:
- Facebook account identifiers: Facebook User ID associated with the connected admin account.
- Page connection data: Facebook Page ID, Page name, Page Access Token, and related user access tokens required to call Meta APIs on your behalf.
- Comment and engagement data (pages_read_engagement, pages_read_user_content): comment text, commenter names, profile pictures, and page-scoped IDs (PSID) of users who comment on your Facebook posts or live videos, so we can detect purchase intent (e.g. "CF" or configured keywords) and create order summaries.
- Messaging data (pages_messaging): Messenger conversation content and related metadata so page administrators can reply to customers in real time inside CFmanager.
- Page metadata and events (pages_manage_metadata, page_events): basic Page configuration and event-related information needed to keep the connected Page in sync with our service.
- Business and catalog context (business_management, catalog_management): business/page linkage and catalog-related identifiers needed for commerce operations tied to the connected Page.
- Public profile (public_profile): basic public profile fields returned by Facebook Login for the connecting user.
2. Permissions We Request
Our Facebook Login currently requests only the following permissions, which match features available in the app:
- public_profile — identify the Facebook user who connects the Page
- pages_messaging — read and send Messenger conversations for customer support and order updates
- pages_read_user_content — read user-generated content such as comments on Page posts
- pages_read_engagement — read Page engagement data needed for live-commerce comment tracking
- pages_manage_metadata — manage Page metadata required to operate webhooks and Page settings used by the app
- page_events — access Page event information related to connected Page activity
- business_management — access business assets needed to manage the connected Page relationship
- catalog_management — access catalog-related data used for commerce workflows on the connected Page
3. How We Use Your Information
We use the data collected from Meta Platforms solely for the following business purposes:
- To identify customers who intend to purchase goods (via comment detection).
- To manage stock, inventory, and order fulfillment for Kanokphan Phathai Limited Partnership.
- To send order invoices, payment confirmations, and delivery tracking updates through Messenger where applicable.
- To provide direct customer support and live-chat communication between the page admin and the end-user.
- We adhere strictly to a Data Minimization Policy. We do not use this data for advertising profiling, nor do we sell Platform Data.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data or Platform Data to third parties. Data is processed internally by Kanokphan Phathai Limited Partnership within Thailand. We will not provide user personal data to public authorities unless strictly required by mandatory laws, official court orders, or criminal investigations.
5. Data Retention and Deletion
We retain Platform Data only for as long as necessary to fulfill the transactions and services described in this policy, or until the user requests deletion.
You can disconnect Facebook in Settings > Facebook Page, which removes stored Page Access Tokens and related connection data from active use. You may also follow our Data Deletion Instructions page or contact us directly. Once a valid deletion request is received, associated Facebook User ID, Page ID, access tokens, comment/PSID data, and Messenger data will be permanently deleted from our servers within 30 days.
You may also revoke our app's access at any time through your Facebook account settings ("Apps and Websites").
6. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data privacy, please contact our Data Controller at:
Entity Name: Kanokphan Phathai Limited Partnership (ห้างหุ้นส่วนจำกัด กนกพรรณผ้าไทย)
Email: Development@kanokpunphathai.com
Country: Thailand