Privacy Policy
Effective date: 4 September 2026 (Asia/Bangkok). Version 1.0.
This policy explains what personal data NearMe.Careers collects, why we collect it, who we share it with, how long we keep it, and what rights you have under the Personal Data Protection Act B.E. 2562 (2019) of Thailand.
1. Who we are
NearMe.Careers ("we", "the app", "the service") is operated by W S Studio Co., Ltd. (บริษัท ดับบลิว เอส สตูดิโอ จำกัด), company registration number 0105569131794.
Registered address: 45 ซ.พระราม2 ที่62 ถ.พระราม2 แขวงแสมดำ เขตบางขุนเทียน กรุงเทพฯ 10150, Thailand.
Contact for privacy questions and requests: hello@getjobnearme.com.
W S Studio Co., Ltd. is the data controller for the personal data described in this policy.
2. How people use NearMe.Careers
- Workers do not create an account. You can browse jobs and apply without a username, a password, or a profile. You verify your phone number once for each application.
- Employers create an account so they can post jobs, see who applied, and manage credits.
- Money never moves through the app. Wages are agreed and paid between the worker and the employer, offline. A PromptPay code shown in the app encodes the worker's own account; we do not receive, hold, or transfer wages.
3. Personal data we collect
- Worker application details — your name, your phone number, and, if you choose to add them, a LINE ID, a WhatsApp number, up to six skill chips you pick from a fixed list, and a message to the employer. These are shown to the employer who posted that job.
- Phone verification — we send a one-time code by SMS and store it as a hash, not as the code itself. The code can be used once, expires after 10 minutes, and verifies the phone for that one application. It does not create a worker account or a login.
- Re-using what you typed before — when you verify the same phone number again for a new application, the name, LINE ID, and skill chips from your most recent application in the last 180 days may be filled in for you. Every field stays editable before you send it, and this creates no account, no login, and no profile.
- Date of birth — when you ask for a verification code we ask for your date of birth, because the service is for people aged 18 and over. We store the date you state.
- App language — the language you are using, so that SMS messages we send you are in that language.
- Payment preference after hiring — for a job marked PromptPay or Either, a hired worker may add a PromptPay identifier so the employer can pay them directly.
- Work record — your applications, the agreed and confirmed wage amounts for jobs you completed, and the ratings connected to them are grouped under an identity keyed to your phone number. You reach this record by verifying your phone again; there is still no password and no profile.
- One-time links — we create expiring, unguessable links so you can check an application, submit a rating, or share a work record without an account. We store only a hash of each link.
- Employer account details — the LINE Login identity we receive from LINE (an account identifier, your display name, and your profile picture), your phone number and its verification, your company or shop name, and, if you add them, a LINE ID, a WhatsApp number, and a shop logo. We do not ask employers for an email address at sign-up; the account record holds an internally generated identifier in that field. Your LINE profile picture stays private unless you choose to use it as your shop picture; if you do, jobseekers see it on your job postings.
- Jobs and content — job titles and descriptions, pay, category, the map coordinates and place name of the workplace, and any images an employer uploads.
- Credits and purchases — the Google Play product, order and purchase-token data needed to confirm a credit purchase and to stop the same purchase being granted twice, and the records of any top-up order. We never receive your card number.
- Ratings — stars, selected tags, optional written feedback, and the moderation decisions on them. Employer ratings may be published. A worker's ratings are shown to an employer when that worker applies to their job; they are not published on a public profile.
- Support — the messages, attachments, and contact details in a support ticket. If you contact us through the NearMe LINE Official Account we also process your LINE user identifier and the messages in that conversation.
- Location — the approximate or precise location of your device, used to find jobs near you. Search coordinates are used to return results; we do not build a movement history from them. Employers deliberately save the location of each job they post.
- Traffic logs — for every request we record the time, the request method and path, the response status, your IP address, your browser or app user-agent string, and a daily-rotating correlation value. Thai computer-crime law requires a service provider to keep this. Codes, tokens, passwords, and request bodies are never written to these logs.
- Security signals — hashed values derived from your phone number, IP address, and device, used to limit how often the same person can send requests, to detect rating fraud, to stop support flooding, and to keep an administrator audit trail.
- Refused under-18 attempts — if the date of birth given is under 18 we keep a minimal record: a hash of the phone number, the stated date of birth, a hash of the IP address, and the job concerned. We keep no name and no readable phone number for someone we refused. This record exists to show a regulator that the age check ran.
- Diagnostics — release builds of the app and the server send crash reports, performance data, device model, operating system version, and app version to Sentry so failures can be investigated.
- Advertising identifiers — the mobile app shows ads through Google AdMob on some worker screens. AdMob may process an advertising identifier and related device data to deliver and measure those ads.
- On-device storage — your language, your theme, an unfinished job posting, and the last successful nearby-job result may be stored on your own device. On the website the browser also keeps a random device value (
nearme_device) for the same purpose as thenm_devcookie below, and an employer's sign-in token is held in the browser's own storage. This data stays on the device and is not sent to anyone else. - Cookies — the website sets two first-party cookies, both HttpOnly, so no script can read them.
nm_applyis short-lived: it carries the proof that you verified your phone for one application, and it expires together with that verification.nm_devis a random device identifier kept for one year; its only use is to let a phone that passed an SMS check within the last 24 hours skip a repeat SMS. It is never used for tracking or advertising, and it holds no name, no phone number, and no application. - No advertising cookies — we set no third-party cookies and no advertising cookies on the website. Because the cookies above are strictly necessary to run the service you asked for, no consent banner is shown for them; you can still delete them at any time in your browser settings, which simply means the next application asks for an SMS code again.
4. Why we use your personal data, and our lawful basis
- To run the service you asked for — showing jobs near you, taking your application, passing it to the employer, letting an employer post and manage jobs, and recording the wage a job was completed at. Lawful basis: performance of a contract, or steps taken at your request before entering one.
- To verify a phone number — so an employer receives real applications and a worker is not impersonated. Lawful basis: performance of a contract and our legitimate interest in a trustworthy service.
- To send service messages by SMS — the verification code, notice that you were hired, and an invitation to rate a completed job. Lawful basis: performance of a contract. These are not marketing messages.
- To publish and show ratings — so both sides can judge who they are dealing with. Lawful basis: legitimate interest in a fair and safe marketplace.
- To run support, moderate content, and handle complaints and takedown notices — Lawful basis: legitimate interest, and legal obligation where a law requires us to act on a notice.
- To confirm credit purchases and keep accounting records — Lawful basis: performance of a contract, and legal obligation under Thai accounting and tax law.
- To keep the service secure and prevent abuse — rate limits, fraud detection, and administrator audit records. Lawful basis: legitimate interest in protecting the service and its users.
- To keep traffic logs — Lawful basis: legal obligation under the Computer Crime Act B.E. 2550 (2007), section 26.
- To refuse users under 18 — Lawful basis: legal obligation and legitimate interest in not exposing minors to day-labour hiring.
- To diagnose crashes and improve reliability — Lawful basis: legitimate interest in a working app.
- Advertising — we do not use your personal data for advertising. We build no advertising profile, we give no application, rating, or work-record data to any advertising platform, and we use none of it to target ads. If this ever changes we will ask for your consent first.
Name, phone number, and date of birth are required to apply for a job. If you do not provide them, we cannot send a verification code and you cannot apply. Everything marked optional above can be left blank.
5. Who receives your personal data
- The employer who posted the job receives the application details you submitted for that job.
- Google Play Billing processes purchases in the mobile app and supplies the purchase records we verify on our server.
- Google AdMob delivers and measures advertising in the mobile app.
- Sentry receives crash and performance diagnostics from release builds.
- Cloudflare R2 stores the images uploaded to the service.
- A Thai SMS gateway provider delivers verification codes and service notices.
- LINE Corporation provides employer sign-in through LINE Login, and delivers support messages through the LINE Official Account when you choose that route.
- OpenStreetMap contributors, CARTO, MapTiler, and Nominatim supply the map tiles, the attribution information shown on the map, and place names.
- Hostinger International Ltd. operates the virtual private server, located in Malaysia, on which the service and its database run.
- Government authorities, courts, and our professional advisers receive personal data where the law obliges us to disclose it or where we need advice to defend a legal claim.
We do not sell your personal data, and we do not share it for anyone else's marketing.
6. Where your data is stored, and transfers abroad
The application servers and the database run on a virtual private server rented from Hostinger International Ltd. and located in a data centre in Kuala Lumpur, Malaysia. Your personal data is therefore stored and processed outside Thailand, and using the service always involves a transfer of personal data to another country under section 28 of the Personal Data Protection Act.
Uploaded images are stored on Cloudflare R2 and delivered through Cloudflare's global network, so those files are stored and served outside Thailand.
Google, LINE, and Sentry operate internationally, so data sent to them may be processed outside Thailand.
Where personal data leaves Thailand — the hosting and database in Malaysia, Cloudflare R2 and Cloudflare's global network, Google, LINE, and Sentry — we rely on the safeguards permitted by sections 28 and 29 of the Personal Data Protection Act. The safeguard we actually rely on today is each provider's own standard hosting, service, and data-processing terms, together with the technical measures described in section 11. We do not rely on an adequacy decision for Malaysia or for any other destination country. We have not concluded a separate data-processing agreement or standard contractual clauses with these providers; their own standard terms are the safeguard we rely on.
7. How long we keep your personal data
- Verification codes — the code is valid for 10 minutes and the token issued after it for 20 minutes. The record is deleted 24 hours after it expires.
- Applications and the data in them — kept for 12 months after the job post expires, then deleted.
- Job posts — a free post is visible for 14 days and a paid post for 30 days; the record is kept for 12 months after that.
- Uploaded job images — deleted 7 days after the job post expires.
- Wage records and the work record built from them — kept for 5 years, matching the period Thai law requires accounting records to be kept.
- Ratings — kept while the related account or work record exists, and for 24 months after the job for a worker's ratings.
- Support tickets and messages — kept for 24 months after the ticket is resolved.
- Purchase and top-up records — kept for 5 years under Thai accounting and tax law.
- Traffic logs — kept for 180 days. Where a log entry still identifies a user, it is kept until 90 days after that user last used the service, as section 26 of the Computer Crime Act requires.
- Refused under-18 records — kept for 12 months.
- Work-record sessions and shared work-record links — expire after 30 days.
- Employer accounts — kept until the employer asks us to delete the account. We then delete it within 30 days, except for records we must keep under accounting, tax, or computer-crime law.
- Administrator audit records — kept for 5 years.
- Nightly database backups — the database is dumped every night to a file kept on the same server as the database, and only the three most recent nightly dumps are kept. A record you delete therefore disappears from the backups within about three days.
8. Your rights as a data subject
- Access — you can ask what personal data we hold about you and get a copy of it.
- Rectification — you can ask us to correct data that is wrong, out of date, or incomplete.
- Erasure — you can ask us to delete your personal data, unless a law requires us to keep it.
- Restriction — you can ask us to stop using your data while a dispute about it is being settled.
- Objection — you can object to processing we carry out on the basis of legitimate interest.
- Portability — you can ask for the data you gave us in a machine-readable form, where that right applies.
- Withdraw consent — where we rely on your consent, you can take it back at any time. Withdrawing it does not undo processing that already happened.
- Complain — you can complain to the Office of the Personal Data Protection Committee (PDPC) in Thailand.
To use any of these rights, write to hello@getjobnearme.com. Because workers have no account, we will ask you to verify the phone number the data is attached to before we act, so that nobody else can reach your data. We answer within 30 days.
9. Advertising, device permissions, and choices
- Location — you can refuse the location permission. The app then uses a clearly labelled default area, or you can pick an area on the map yourself.
- Optional fields — LINE, WhatsApp, and the message to the employer can be left blank. PromptPay is asked for only after you are hired, and only when the employer chose that payment method; cash stays available where the employer offers it.
- LINE support — using the LINE Official Account is your choice. Web support is available instead.
- Advertising — you can manage advertising choices in your device or Google account settings, including resetting or deleting your advertising identifier.
- On-device data — clearing the app's storage removes the language, theme, drafts, and cached results held on your device.
10. Age limit — 18 and over
The service is for people aged 18 and over. Applying requires a date of birth, and an applicant who states an age under 18 is refused before any verification code is sent. The limit is enforced in the code, not only stated in this policy. If you believe a person under 18 has used the service, write to hello@getjobnearme.com and we will delete their application data. The one thing we keep is the minimal refusal record described in section 7 — a hashed phone number, the stated date of birth, a hashed IP address, and the job concerned — because we have to be able to show a regulator that we declined.
11. How we protect your data
- Traffic between the app and our servers is encrypted in transit.
- Verification codes, session tokens, and one-time links are stored as hashes, never in a form we could read back.
- Phone numbers, IP addresses, and device identifiers used for abuse prevention are stored as hashes.
- Access to the administration tools requires a separate administrator account, and every administrator action is written to an audit record.
- Traffic logs are chained with a cryptographic hash so that an entry edited afterwards can be detected.
- No system is perfectly secure. If a data breach puts your rights at risk we will notify the PDPC and, where required, you.
12. Changes to this policy, and how to contact us
If we change this policy we will update the date at the top. If a change materially affects how we use your personal data we will tell you in the app before it takes effect.
Data controller: W S Studio Co., Ltd. (บริษัท ดับบลิว เอส สตูดิโอ จำกัด), registration number 0105569131794.
Address: 45 ซ.พระราม2 ที่62 ถ.พระราม2 แขวงแสมดำ เขตบางขุนเทียน กรุงเทพฯ 10150, Thailand.
Email: hello@getjobnearme.com.
We have not appointed a Data Protection Officer under section 41 of the Personal Data Protection Act. Privacy questions and requests go to hello@getjobnearme.com, which the company reads and answers.
You can complain to the Office of the Personal Data Protection Committee, Bangkok, Thailand.