1. Who this covers, and the two roles
360Nook is operated by 360Nook, a business established in Thailand. Contact: [email protected]
We identify the operator by its trading name and a working contact address rather than by an individual's name or street address. That is what a data subject actually needs in order to reach us, and it is what Thailand's PDPA and the GDPR require of a controller — neither asks for a named person to be published.
Two quite different relationships run through this platform, and the difference decides who is answerable for what:
- You, our customer. You create an account, you are billed, and we decide what to do with your account data. For this we are the controller.
- Your contacts. The people whose names, numbers and conversations you load into your workspace. We hold them on your instructions, and for these we are the processor — you are the controller.
If you are one of our customers' contacts and want your data corrected or removed, ask the business you dealt with. They control it. If you cannot reach them, write to us and we will pass your request on.
2. What we collect about you, our customer
- Account details — your name, email address, password (stored only as a hash, never in a form we can read), avatar, language and default workspace.
- Workspace details — the workspace name, timezone, currency, your role in it, and who invited whom.
- Usage records — when you last signed in, what your workspace has used (messages sent, AI tokens consumed), and audit entries for significant actions.
- Billing details — your plan and its status. Card numbers never reach our servers; they are entered directly with the payment provider.
3. What you put into your workspace
This is your data, not ours. It includes:
- Contacts — names, email addresses, phone numbers, business names, addresses, tags, custom fields, notes, engagement scores, and an activity timeline.
- Conversations — the content of emails, SMS and chat messages sent and received through the platform, with their delivery status and timestamps.
- Calendars and appointments — bookings, who they are with, the answers to any questions your booking form asks, and — where a booking form offers a marketing consent box — the date it was ticked and the exact sentence agreed to. That wording is stored deliberately: consent is only evidence if you can show what was actually agreed.
- Files — anything uploaded to Media Storage, including images and documents.
- Sites, funnels, forms and surveys — their content, and the submissions visitors make to them.
- Payments you take — orders, invoices, subscriptions and transactions.
We do not sell any of it, and we do not use your contacts or their messages to train AI models.
4. Visitors to pages you publish
When someone visits a site, funnel or booking page you publish through 360Nook, we record what is needed to make those pages work and to report on them: page views, which variant of a split test they were shown, and the referral that brought them.
Three cookies do this, and no others are set for tracking:
| Cookie | What it does |
|---|---|
nook_vid | An anonymous visitor id, so an affiliate referral can be credited |
nook_seen | Remembers which split-test variant a visitor was shown, so the page does not change under them |
nook_v_optin | Remembers that a visitor has already submitted a form, so they are not asked twice |
We do not use advertising cookies, and we do not share visitor data with ad networks.
Signing in sets a session cookie (authjs.session-token) and a cookie recording
which workspace you are viewing (nook_workspace). These are necessary for the
platform to work and are not used for tracking.
5. Artificial intelligence, and what leaves our servers
This is the section most worth reading closely, because it is the one where your content goes somewhere else.
When you use an AI feature — a conversation agent, content generation, a knowledge-base answer — the relevant content is sent to a third-party AI provider to be processed. Depending on the model chosen, that provider is Anthropic, OpenAI, or Google. What is sent is whatever that feature needs: for a conversation agent, the messages in that conversation; for content generation, your prompt and the surrounding material.
Two arrangements are possible and the difference matters:
- Your own API key. If your workspace has its own provider key configured, the request goes to your account with that provider, under your terms with them. Your key is encrypted at rest.
- Our key. Otherwise the request goes through our account with that provider.
In both cases the content is transmitted to and processed by that provider, outside Thailand, and is subject to their terms and their retention. If that is unacceptable for particular data, do not put that data through an AI feature.
6. Other companies we rely on
| Purpose | Provider | What reaches them |
|---|---|---|
| Email delivery | Brevo (SMTP) | The address, subject and content of each email sent |
| SMS, voice and phone numbers | Twilio | Numbers, message content, call metadata |
| AI processing | Anthropic, OpenAI, Google | See section 5 |
| Payments you take | Your chosen gateway — Stripe, PayPal, Omise, Xendit, PayMongo, Midtrans, VNPay, Billplz, Komoju, Tap, PayTabs, Mollie, Mercado Pago or Razorpay | Payment details, handled by them directly |
| Hosting | Our own server infrastructure | Everything above, at rest |
Where you connect an integration yourself — a social account, a CRM, a calendar — data flows to that service on your instruction and under its own policy.
7. International transfers
Our servers are in Thailand. The providers in sections 5 and 6 operate outside Thailand, in the United States and elsewhere, so using those features transfers data internationally.
If you are in the EU or UK, or your contacts are, this is an area a lawyer should review before you rely on it. We have not yet put standard contractual clauses in place, and we would rather say so than imply otherwise.
8. How long we keep things
- While your account is open, your data is kept until you delete it.
- Deleting a record in the platform usually marks it deleted and hides it, rather than erasing it immediately — this is what makes an accidental deletion recoverable. Tell us if you need something erased outright and we will do it.
- Closing an account or deleting a whole workspace is done by asking us — write to [email protected] and we will erase it. There is no self-service button for this yet. We would rather say so than imply one exists: the database is built to remove a workspace's contacts, conversations, appointments, files, sites and payment records along with it, but today that is run by us on request rather than by you.
- Backups are kept for disaster recovery and are overwritten on a rolling basis, so deleted data can persist in a backup for a short period after it is gone from the platform.
9. Security
Passwords are stored only as hashes. Provider credentials and API keys are encrypted at rest. Every workspace's data is isolated at the database level, so one customer's queries cannot reach another's rows. Access is over HTTPS.
No system is perfectly secure. If you believe your account has been compromised, write to [email protected] immediately.
10. Your rights
You may ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to [email protected]. We will respond within 30 days.
If you are a contact of one of our customers rather than a customer yourself, see section 1 — ask the business you dealt with first.
You can stop marketing from a business using 360Nook by using the unsubscribe link in any email, or replying STOP to an SMS. That is honoured automatically and immediately across every channel.
11. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18.
11a. Connected accounts, and what we do with Google user data
Some features only work if you connect an account you already have elsewhere — a calendar, a mailbox, a social page, a payment provider. Connecting one is always your choice, it is never required to use 360Nook, and you can disconnect it at any time from the screen you connected it on.
When you disconnect, we delete the stored credentials. Anything already created in that account — a booking written into your calendar, a message already sent — stays where it is. Those are records of things that really happened, often with a customer involved, and deleting them because you unlinked an integration would destroy data you never asked us to touch.
Google user data
360Nook's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
If you connect a Google account, this is the whole of it:
| Permission we ask for | Why | What we do with it |
|---|---|---|
calendar.calendarlist.readonly — the names of your calendars | So you can choose which one to write bookings into, and which to check for clashes | Shown to you in the Connections screen. We store only the ids you pick. |
calendar.freebusy — busy intervals | So we never offer a time when you are already booked | Read at the moment a slot is offered. Returns start and end times only. |
calendar.events — create and update events | So a booking appears in your calendar the moment it is made | We write only appointments made through 360Nook, and keep that event's id so we can move or remove that same event later. |
We deliberately do not ask for calendar.readonly or full calendar access.
Those would let us read the contents of every event you have, and we have no
reason to. The narrow permissions above are what the product actually uses.
And, plainly, the things we do not do:
- We do not read the contents of your existing calendar events. Busy times are fetched as intervals — start and end — not as event bodies.
- We do not use Google user data to train any AI or machine-learning model, our own or anyone else's.
- We do not sell Google user data, and we do not transfer it to third parties except as needed to provide the feature you switched on, or where the law requires it.
- We do not show you advertising based on it.
- Only you, and people you have given access to your workspace, can see it.
Access tokens are stored encrypted (AES-256-GCM) and are never written to logs or shown on screen. Revoking access from your Google Account permissions page stops everything immediately, with no action needed here.
12. Changes
If this policy changes materially we will say so in the platform before the change takes effect. Previous versions remain available, so it is always possible to establish what this policy said on a given date.