⌕
← Golden Gate GGT

KARENNI TRAVEL & LOGISTICS

Privacy policy

Effective 8 October 2026 · Policy text in English

This policy covers Karenni Travel & Logistics, the Golden Gate customer app, goldengateggt.com, and the connected staff and driver workspaces. Golden Gate GGT Co., Ltd. is responsible for the personal data it processes for these services.

Information we use

We process account names, email addresses, sign-in identifiers, salted password hashes where password sign-in is used, session tokens, account preferences, and verified phone numbers. Shipment information includes sender and recipient names, phone numbers and addresses, parcel descriptions, estimated and measured weights, photos, pickup instructions, driver assignments, custody events, payment references and receipts. When you supply another person’s details, provide accurate information and make them aware of its use for the shipment.

Why we use it

We use information necessary to take steps at your request and perform delivery arrangements, contact you, verify pickup numbers, maintain custody and resolve service issues. Accounting and other records may be retained to meet applicable legal obligations. Access controls, security logs and fraud prevention support our legitimate interests in protecting customers and the service. Optional analytics and device notifications follow your choices; where consent is required, you may withdraw it without affecting earlier lawful processing. Required booking information is identified in the forms; without it we may be unable to arrange a pickup or delivery.

Thai phone verification and pickup calls

deeSMSX processes the Thai mobile number and verification request to deliver and validate SMS codes. Our server stores the phone number, a short-lived challenge and provider reference, verification time and attempt limits. We do not store the entered OTP as a customer record. A successful OTP proves access to that number at verification time; it is not government-ID verification. You can select a previously verified number or verify a new one. The selected number is recorded for that pickup and shared with authorized branch staff and the assigned driver for calls about the pickup. These messages are for verification, not marketing.

Identity documents and selfies

For pickup intake, authorized staff collect a sender identity document image and a selfie in the restricted identity area after explaining the purpose and retention. Do not put identity images in ordinary parcel photos or notes. These images are encrypted and restricted to the owner, administrators and originating branch manager; access is logged. They are unavailable to customers, couriers and public tracking. Images become inaccessible after 30 days and are removed by the scheduled expiry process; they are excluded from routine parcel-photo backups. There is no automated facial recognition in this workflow. Staff verification records are separate from OTP verification.

Who receives information

Authorized staff, assigned drivers and delivery partners receive the details needed for their work. Amazon Web Services hosts the application. Google provides optional sign-in; Firebase supports configured authentication, optional notifications and optional analytics. deeSMSX handles phone verification. Apple and Facebook sign-in are used only when an enabled option is offered and selected. Provider account enrollment alone does not enable a login method. We may disclose information when required by law or needed to handle a legal claim. We do not sell personal data or use it for advertising in this app.

International processing

Hosting, authentication, notification and SMS providers may process data in countries other than your own. Shipment details may also be shared across borders where your requested delivery requires it. We limit disclosures to their service purpose and use applicable contractual, access-control and other safeguards for international transfers. Contact us to ask about the arrangements relevant to your shipment.

Tracking, devices and choices

Anyone with a valid tracking reference can see limited public status and handover history. Keep the reference private. Public tracking does not expose the full customer account or restricted identity images. Camera access is optional until you choose a camera-based feature. Biometrics, where enabled on your device, protect local access; the app does not receive your biometric template. You can manage notification and analytics preferences in the app and device settings. Optional analytics excludes parcel descriptions, contact details and identity images. Necessary session cookies or secure app tokens keep you signed in.

Retention and deletion

Account profile, saved addresses, verified numbers, sign-in links and device registrations are retained while needed for your account and removed when its deletion is fulfilled. Business records, including shipment contacts, custody evidence, payments and security history, may be retained when necessary for ongoing delivery, accounting, fraud prevention, disputes or legal obligations; staff must record a reason and review date when fulfilling a deletion request involving shipment records. These records are not automatically deleted merely by closing an account. We assess the necessary period rather than promise one period for all business records. Routine daily backups rotate over 14 days; restricted manual release or incident-recovery copies can remain longer until their recovery purpose ends. Deleted data in backups is not used for ordinary operations, and deletion must be reapplied if a backup is restored. Restricted ID images follow the separate 30-day limit above.

Your rights and how to request them

Subject to applicable law, you may request access or a copy, correction, erasure, restriction, portability, object to processing, or withdraw consent. You may complain to Thailand’s Personal Data Protection Committee or another competent authority. Use Account → Delete account in the customer app, the Delete account page on this website, or contact@goldengateggt.com. We may need to verify identity and authority before disclosing or deleting data. A request is not automatically a completed deletion: we explain the next steps, expected completion time and any necessary retained records. We process requests without undue delay within applicable requirements. Please do not send passwords, OTPs or government-ID photos by email.

Contact and changes

Use the company contact details below for privacy questions and requests. Material changes will be reflected in this notice and brought to your attention where required. The effective date identifies the published policy version.

Company and contact

Golden Gate GGT Co., Ltd.
บริษัท โกลเดนเกต จีจีที จำกัด
Registration number: 0585568000293

24/15 Moo 12, Ban Kat, Mae Sariang, Mae Hong Son 58110, Thailand
24/15 หมู่ที่ 12 ตำบลบ้านกาศ อำเภอแม่สะเรียง จังหวัดแม่ฮ่องสอน 58110

contact@goldengateggt.com