Khmercow

Open the app Terms Support Your data Delete account
KHMERCOW MARKETPLACE - PRIVACY POLICY

Version 2.1
Effective Date: September 18, 2026
Last Updated: September 18, 2026

OPERATOR OF THE PLATFORM
  KhmerCow Marketplace is an online marketplace operated as a sole
  proprietorship by an individual trader based in the Kingdom of Cambodia. It is
  not incorporated as a company and therefore has no business registration
  number.

  General enquiries: info@khmercow.com
  Support, complaints and data-protection requests: support@khmercow.com

  A postal address for formal correspondence is available on request from
  support@khmercow.com.

  This policy is published in English. A Khmer translation may be provided for
  convenience; if the two versions differ, the English version governs.

---------------------------------------------------------------------------
INTRODUCTION
---------------------------------------------------------------------------

Welcome to KhmerCow ("KhmerCow", "we", "us", or "our"). KhmerCow operates a
comprehensive online marketplace platform connecting buyers, independent sellers
("Vendors"), and administrators through mobile applications, websites, APIs, and
related digital services (collectively, the "Platform" or "Service").

We respect your privacy and are committed to processing personal data in a
transparent, lawful, and secure manner consistent with applicable data protection
laws. This Privacy Policy explains:

  - What personal data we collect and from whom
  - How we use and store that data
  - With whom we share it and why
  - The technical and organisational security measures we apply
  - Your rights regarding your personal data
  - How to contact us with privacy inquiries or data deletion requests

By accessing or using the Platform, you acknowledge and accept the data practices
described in this Privacy Policy. If you do not agree with this Policy, please
discontinue use of the Platform.


---------------------------------------------------------------------------
1. INFORMATION WE COLLECT
---------------------------------------------------------------------------

We collect personal data in three ways: information you provide directly,
information collected automatically when you use the Platform, and information
received from third-party authentication or payment services.

1.1 Account & Identity Data
  - Full name (first name, last name)
  - Username (unique identifier; auto-generated for phone sign-up users,
    e.g., "user_855123456789"; user-chosen for email sign-ups)
  - Email address (optional for phone-only accounts; cached from our
    authentication system for display and quick queries)
  - Phone number with country code (optional for email-only accounts; cached
    from our authentication system)
  - Profile photograph (optional)
  - Bio / profile description (optional)
  - Account role: buyer, vendor, or administrator
  - Authentication method in use: email/password, phone OTP, Google Sign-In,
    Facebook Login, or Sign in with Apple
  - Firebase UID (internal authentication identifier assigned by Firebase)
  - The account ID assigned by Google, Facebook or Apple, if you sign in with
    that provider
  - Optional social media contact fields: Telegram, WhatsApp, Facebook,
    Instagram, WeChat
  - Wishlist / saved products
  - Followed stores and followed user accounts
  - Recently browsed products -- a short list of the products you have opened,
    kept on your account and used, together with your order history, only to
    personalise your recommendations. Never shared with stores or other users.

  Data we receive from Facebook Login and Sign in with Apple
  These are optional ways to sign in. If you choose one, we receive only the
  following, through Google Firebase Authentication:

  - Facebook Login (Meta Platforms, Inc.): your app-scoped Facebook user ID,
    your name, your email address (only if you allow it), and your profile
    picture. We request only the "public_profile" and "email" permissions.
  - Sign in with Apple (Apple Inc.): your Apple user ID, your name (Apple sends
    it only the first time you sign in), and your email address or the private
    relay address Apple creates for you.

  We do NOT receive your Facebook or Apple password, your friends list, or your
  posts. We never post to Facebook on your behalf, and we do not use this data
  for advertising. It is used only to create your KhmerCow account, sign you in,
  and show your name and photo in the app.

  This data is deleted with your account -- see
  https://khmercow.com/account-deletion. You can also disconnect KhmerCow at any
  time: in Facebook, Settings & privacy > Settings > Apps and websites;
  for Apple, your Apple ID settings > Sign in with Apple.

1.2 Store & Business Data (Vendors only)
  - Store name, auto-generated URL slug, description, and category
  - Business email address, business phone number, and physical business address
  - Store geolocation (longitude/latitude coordinates) for nearby-store features
  - Business hours
  - Store logo and banner images (stored in configured cloud media provider)
  - Published social media links: Facebook, Instagram, Twitter/X, Telegram,
    WhatsApp, Messenger, WeChat, and website URL
  - Business establishment date
  - Return policy text and shipping policy text
  - Per-channel notification preferences: email, Telegram, SMS, and push
  - OTP verification status: phone verified, email verified (with timestamps)
  - Store approval status and approval/rejection history

1.3 Product Data (Vendors only)
  - Product name, description, and category
  - Listed price and currency (USD or KHR)
  - Original price, sale price, discount type, and discount value
    (promotion audit trail)
  - Inventory quantity, product condition, and SKU
  - Product type: stockable (inventory-tracked) or non-stockable
    (made-to-order / service-based)
  - Product images and videos (stored in configured cloud media provider)
  - Active promotion or featured listing status

1.4 Order & Transaction Data
  - Order recipient: first name, last name, phone number, alternate phone number,
    and email address (optional)
  - Delivery address: state/province, city, locality/street, postal code
  - Delivery landmark and delivery notes (optional)
  - Address type: home, work, or other
  - GPS coordinates or map pin for the delivery location (only if you provide it)
  - Delivery location photograph (optional; uploaded at checkout)
  - Ordered products: names, quantities, unit prices, currencies, and applied
    discounts
  - Discount/promotion audit trail: original price, discount type, discount
    amount, and final sale price
  - Order payment method: Cash on Delivery (COD) for buyer marketplace orders
  - Order status history: pending, processing, shipped, delivered, cancelled,
    rejected
  - One-time delivery confirmation token: 6-digit, single-use, 24-hour expiry
  - Vendor platform payment: ABA PayWay KHQR transaction reference, payment
    status, and amount (for subscription and promotion package fees)
  - Stripe Customer ID (legacy; retained from prior subscription payment
    processing where applicable)
  - Last saved delivery address per registered user (name, phone, email, address
    fields, and GPS coordinates if provided)

1.5 Browsing Without an Account
  You may browse the Platform, view stores and products, and use search without
  creating an account. In that case we collect no account or identity data from
  you -- only the device and technical data in section 1.6 and the usage data in
  section 1.7.
  Placing an order requires a KhmerCow account, so that you can track the order
  and the store can contact you about the delivery.

1.6 Device & Technical Data
  - Device type, operating system version, and app version
  - Language and locale settings
  - Firebase Cloud Messaging (FCM) token (required to deliver push notifications)
  - Firebase App Check attestation token (used to verify app authenticity and
    prevent unauthorized API access)
  - Per-install device identifier, transmitted as an "x-device-id" HTTP request
    header. This identifier is randomly generated by the app on installation and
    stored locally on your device. It is used exclusively for brute-force abuse
    detection and device-level security blocking. It is not a hardware identifier.
    We do not collect IMEI, MAC address, serial number, or similar hardware IDs.
  - IP address (used for security monitoring, rate limiting, and fraud prevention)
  - User-agent string (browser or app client information)
  - JWT authentication tokens and refresh tokens (stored securely on your device
    using encrypted local storage)
  - Approximate geolocation inferred from IP address (country/region level only)
  - Device location, when you grant permission. We explain why and ask for your
    agreement before your device shows its own permission prompt. It is used in
    two ways, and only while you are actively using the app -- never in the
    background:
      * Nearby discovery (home screen and "near me" search): your position is
        rounded to roughly 1 km before it is sent to us, and is used only to find
        nearby stores and products. It is not stored against your account.
      * Precise location: collected only when you explicitly place a pin --
        setting a delivery address (see 1.4) or placing your store on the map.
        This is saved with that address or store.
    You can revoke location access at any time in your device settings; the app
    continues to work without it.

1.7 Usage & Analytics Data
  - Screens visited, products viewed, and search queries performed
  - Voice search query transcripts (text only; audio is not permanently stored)
  - Image search label metadata (descriptive labels from uploaded images;
    images are not permanently stored)
  - Cart additions/removals, checkout steps, and order placement events
  - Store page views, store follows/unfollows, and product wishlist actions
  - Event metadata per tracked action: IP address, user agent, HTTP referrer,
    response time, and timestamp
  - Session start/end events, session duration, and approximate screen time
  - Notification delivery status per channel: confirmation timestamps and
    delivery error records
  - In-app error events and API error responses

1.8 Security & Audit Data
  - Login attempt records: successful and failed authentication events
  - OTP generation timestamps and verification outcomes
  - Brute-force flags: blocked IP address records (block type, reason, number
    of failed attempts, expiry time) and blocked device identifier records
  - Account lockout events and lockout expiry timestamps
  - Administrator actions affecting user or store records, stored in a
    tamper-evident audit log

1.9 Review & Rating Data
  - Product review text and star rating (1-5 stars)
  - Optional store rating (1-5 stars) and store review text submitted alongside
    a product review
  - Reviewer account name and user ID
  - Review moderation status: pending, approved, flagged, or removed; and the
    reason for removal if applicable


---------------------------------------------------------------------------
2. HOW WE USE YOUR INFORMATION
---------------------------------------------------------------------------

We use personal data strictly for the following purposes:

  PURPOSE                                  | LEGAL BASIS
  -----------------------------------------|----------------------------
  Create and manage your account           | Performance of contract
  Authenticate you securely (OTP, JWT)     | Performance of contract
  Process and fulfil orders                | Performance of contract
  Send transactional notifications         | Performance of contract
  Verify store registration for Vendors    | Performance of contract
  Display your store and product listings  | Performance of contract
  Process Vendor platform payments (KHQR)  | Performance of contract
  Deliver push notifications (FCM)         | Performance of contract
  Personalise product recommendations      | Legitimate interest
  Send platform news and promotions        | Consent (opt-in, Settings)
  Detect fraud, abuse, and security threats| Legitimate interest
  Provide Vendor analytics dashboard       | Legitimate interest
  Monitor platform performance and errors  | Legitimate interest
  Improve the Platform via analytics       | Legitimate interest
  Comply with applicable legal obligations | Legal obligation

We do NOT use your personal data for behavioural advertising, and we do NOT
sell your data to advertising networks or data brokers.


---------------------------------------------------------------------------
3. DATA SHARING AND THIRD PARTIES
---------------------------------------------------------------------------

We do not sell your personal data to any third party.

We share data only in the following limited circumstances:

3.1 With Vendors for Order Fulfillment
  When you place an order, the fulfilling Vendor receives your name, phone
  number, email address (if provided), and full delivery address (including
  GPS coordinates and delivery notes if provided) solely for the purpose of
  fulfilling that order.

3.2 Public Store Profiles
  Vendor store names, published contact details, store locations, product
  listings, prices, and customer reviews are visible to all Platform users and
  may be indexed by external search engines.

3.3 Third-Party Service Providers
  We engage the following trusted service providers who process data on our
  behalf and strictly under our instruction:

  Authentication & App Integrity (Google / Firebase):
  - Firebase Authentication -- account creation, sign-in, and token issuance
  - Firebase App Check -- app attestation to block unauthorized API access
  - Firebase Cloud Messaging (FCM) -- push notification delivery
  - Google Sign-In -- optional social authentication

  Optional Sign-In Providers:
  - Meta Platforms, Inc. -- Facebook Login (optional social authentication)
  - Apple Inc. -- Sign in with Apple (optional social authentication)

  Cloud Infrastructure & Hosting:
  - Railway -- primary API server hosting
  - MongoDB Atlas (or equivalent) -- cloud database hosting
  - Cloudflare, Inc. -- network security, DNS and content delivery for our
    website and API
  - Redis -- OTP storage, rate limiting, and result caching (when configured)

  Media Storage & Delivery (admin-configured; one or more may be active):
  - Cloudinary -- image/video upload, transformation, optimisation, and CDN
  - Firebase Storage / Google Cloud Storage -- media storage and delivery
  - Amazon Web Services S3 (AWS S3) -- media storage and delivery
  - Custom storage providers (when administrator-configured)

  Maps & Location Services:
  - Google Maps Platform -- map display, address geocoding, and delivery
    location pin selection

  Email Delivery (admin-configured; one or more may be active):
  - AWS Simple Email Service (AWS SES)
  - Brevo (formerly Sendinblue)
  - Resend
  - Twilio SendGrid or SMTP relay

  SMS / Phone Verification:
  - Twilio -- SMS OTP delivery
  - Firebase Phone Authentication -- phone number OTP (where configured)

  Vendor Notifications (optional; configured per Vendor):
  - Telegram Bot API -- order and store event notifications for Vendors who
    configure a Telegram bot connection for their store

  Payment Processing:
  - ABA PayWay (Cambodia Commercial Bank / Bakong KHQR) -- payment gateway
    for Vendor subscription fees and promotion package fees via KHQR QR code.
    ABA PayWay receives the transaction amount, reference ID, and an
    HMAC-SHA512-signed request payload. ABA PayWay's privacy policy applies
    to data processed on their systems.
  - Stripe -- legacy payment processor. KhmerCow may retain historical Stripe
    Customer IDs from prior subscription transactions.
    (See: https://stripe.com/privacy)

  Search & AI Services (optional; admin-configured):
  - Google Cloud Speech-to-Text -- voice search audio transcription
  - Google Cloud Vision AI -- image label detection for image-based search
  - Google Translate -- bilingual (Khmer / English) query translation
  - MyMemory Translation API -- supplementary translation for bilingual search
  - LibreTranslate -- additional fallback translation provider

3.4 Legal Disclosure and Safety
  We may disclose personal data if required by applicable law, regulation, valid
  legal process, or governmental request, or where necessary to protect the
  rights, property, or safety of KhmerCow, its users, or the public. We will
  notify affected users of such disclosures to the extent permitted by law.


---------------------------------------------------------------------------
4. SPECIAL FEATURES: VOICE SEARCH AND IMAGE SEARCH
---------------------------------------------------------------------------

4.1 Voice Search
  When using voice search, your device may perform speech-to-text transcription
  locally. If server-side transcription is enabled by administrators, audio may
  be sent to our server and processed by Google Cloud Speech-to-Text. Raw audio
  recordings are not permanently stored after transcription. The resulting text
  transcript may be temporarily retained to execute the search query and may be
  stored for analytics, security monitoring, and debugging for a limited period.
  For bilingual search (Khmer to English or English to Khmer), the transcript
  may be sent to Google Translate, MyMemory Translation API, or LibreTranslate.

4.2 Image Search
  When using image search, the image you upload is processed to detect visual
  labels and match products. When enabled by administrators, Google Cloud Vision
  AI is used for label detection. Uploaded images are not permanently stored in
  our primary database. Search results may be cached (keyed by an image hash and
  search parameters) for approximately 10 minutes for performance. Non-image
  metadata, such as detected labels and result counts, may be retained for
  analytics and service improvement purposes.

4.3 In-App Chat
  You can message a store directly. Message content, sender, and timestamp are
  stored both in our database and in Google Cloud Firestore (which is what makes
  messages appear in real time). Images sent in chat are stored in Google
  Firebase Storage. Read receipts and any report you file are also stored.

  Encryption and its limits: message text sent from a buyer's device is
  encrypted (AES-256-GCM) before storage. This is NOT end-to-end encryption --
  the key is held by KhmerCow, so we are technically able to decrypt messages.
  We use that ability only to investigate reports and to comply with a lawful
  request. Replies sent from a store are not encrypted at rest, because store
  staff accounts cannot access the conversation key. Please do not send
  passwords, card numbers, or identity documents through chat.

  Moderation: you can report a message. Reports are reviewed by KhmerCow
  administrators, who can see the reported conversation. Administrators can
  permanently delete any message and can close or flag a conversation. A store
  owner can grant staff permission to read and reply to that store's
  conversations; staff never see conversations belonging to other stores.

4.4 Who Inside KhmerCow Can See Your Data
  KhmerCow administrators use an internal web panel. Through it they can:
  - View any account's name, email, phone, role and status; suspend or
    reactivate it.
  - View every order platform-wide, including delivery addresses and contact
    details, and change an order's status.
  - View, approve, reject and delete stores, products and reviews.
  - View conversations and message previews for moderation, and permanently
    delete messages.
  - View security records, including login attempts with IP address and device
    identifier, and block an IP address or device.
  - View platform-wide analytics, including search terms, and delete a specific
    user's or store's analytics records.
  - Send notifications and emails to all users or a selected group.

  Administrator access is limited to accounts KhmerCow has explicitly granted
  the administrator role, administrative actions against an account or store are
  written to an audit log, and there is no facility for staff to sign in as you
  or to view your password. We access your data only to operate the Platform,
  investigate reports and abuse, provide support, and meet legal obligations.


---------------------------------------------------------------------------
5. DATA RETENTION
---------------------------------------------------------------------------

We retain personal data only as long as necessary for the purposes described
in this Policy or as required or permitted by applicable law.

  DATA TYPE                             | TYPICAL RETENTION PERIOD
  --------------------------------------|----------------------------------------
  OTP verification codes                | ~10 minutes (automatic expiry)
  Pending signup data (pre-verify)      | ~15 minutes (automatic expiry)
  Image search result cache             | ~10 minutes (automatic expiry)
  System / operational logs             | ~30 days (administrator-configurable)
  Security / audit logs                 | ~365 days (administrator-configurable)
  Blocked IP records                    | Until expiry or admin unblock
  Blocked device identifier records     | Until expiry or admin unblock
  FCM push notification tokens          | Until logout, account deletion, or
                                        | notification permission revoked
  Analytics events                      | 90 days (deleted automatically)
  Order and transaction records         | As required for history, dispute
                                        | resolution, and legal compliance
  Stripe Customer IDs (legacy)          | Until manually purged
  Active account data                   | Duration of account activity

5.1 Account Deletion
  You may request account deletion at any time by emailing info@khmercow.com
  or using the in-app account deletion feature. Upon receiving a valid deletion
  request:

  - Your account is deactivated immediately and hidden from the Platform.
  - Personal data no longer required (saved delivery addresses, FCM tokens,
    preferences) is scrubbed at once.
  - A grace period of 30 days applies, so that an accidental deletion can be
    reversed by contacting support.
  - After 30 days a scheduled process irreversibly erases your personal data:
    your name, email address, phone number, profile photograph, bio and social
    handles are destroyed, and your sign-in identities are removed.
  - Order and payment records survive, because Cambodian tax and commercial law
    requires them to be kept for at least 7 years. They remain linked to an
    account shell that no longer identifies you.
  - Reviews you wrote keep their text and rating, with the author shown as
    "Deleted User", so other shoppers do not lose a product's rating history.
  - Vendors: active subscription and promotion records may be retained in
    minimal form for accounting compliance after account deletion.

  Google Play account deletion request page:
  https://khmercow.com/account-deletion


---------------------------------------------------------------------------
6. DATA SECURITY
---------------------------------------------------------------------------

We implement industry-standard administrative, technical, and organisational
security controls:

  - TLS/HTTPS encryption for all data transmitted between the app, web
    platform, and our servers.
  - Bcrypt password hashing with a minimum cost factor of 12 rounds for all
    stored credentials.
  - JWT access tokens with short expiry intervals and automatic refresh token
    rotation. Sessions are invalidated on password changes or detected anomalous
    activity.
  - OTP codes are cryptographically random (6-digit), expire after 10 minutes,
    and are invalidated upon first successful verification. A maximum of 5
    verification attempts and 3 resend requests per hour are enforced.
  - Firebase App Check attestation to prevent unauthorised API access from
    non-genuine or modified app clients.
  - Brute-force protection: IP addresses and x-device-id identifiers are
    monitored for repeated failed authentication attempts. Exceeding configured
    thresholds results in automatic temporary account lockout and/or IP- or
    device-level blocking by the system.
  - Rate limiting applied to all sensitive endpoints: authentication, OTP
    generation and verification, search, and payment endpoints.
  - HTTP security headers enforced on all API responses via Helmet.js, including
    HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options,
    Referrer-Policy, and Permissions-Policy.
  - Input sanitisation and NoSQL injection prevention applied to all API inputs.
  - All administrative actions are recorded in a tamper-evident audit log
    retained for up to 365 days.
  - Sensitive credentials and API keys are stored in environment variables and
    are never exposed to client applications.

No internet-based system is completely secure. You are responsible for
maintaining the confidentiality of your account credentials. If you suspect
unauthorised access, contact us immediately at info@khmercow.com.


---------------------------------------------------------------------------
7. YOUR PRIVACY RIGHTS
---------------------------------------------------------------------------

Depending on your jurisdiction and applicable law, you may have the following
rights regarding your personal data:

  - Right of Access -- Request a copy of the personal data we hold about you.
  - Right to Rectification -- Request correction of inaccurate or incomplete
    data.
  - Right to Erasure -- Request deletion of your personal data ("right to be
    forgotten"), subject to lawful retention obligations.
  - Right to Data Portability -- Request your data in a machine-readable,
    portable format. Open Settings and tap "Request My Data" to download a JSON
    copy. This works in the Android app, the iOS app and on the web, and is
    limited to three requests per day. Full instructions, and the list of what
    the file contains, are at https://khmercow.com/data-request
  - Right to Restrict Processing -- Request that we limit how we process
    certain data.
  - Right to Object -- Object to processing activities based on legitimate
    interest.
  - Right to Withdraw Consent -- Where we rely on consent (e.g., location or
    microphone access), you may withdraw consent at any time via device settings.

To exercise any right, contact us at info@khmercow.com. We will respond within
30 days. We may need to verify your identity before processing sensitive
requests.

Note: Transactional communications essential to service operation (such as OTP
codes and order status notifications) cannot be permanently opted out of while
your account remains active, as they are required for the security and
fulfillment of your transactions.


---------------------------------------------------------------------------
8. LOCAL STORAGE AND TRACKING TECHNOLOGIES
---------------------------------------------------------------------------

KhmerCow mobile applications use the following on-device data storage:

  - Encrypted secure storage (flutter_secure_storage) -- to store JWT access
    and refresh tokens securely on the device using platform keystore/keychain.
  - Shared preferences -- to store non-sensitive preferences: display currency
    selection and locale/language setting.
  - Per-install x-device-id -- a randomly generated identifier stored locally
    on the device and sent as an HTTP header. Used exclusively for brute-force
    abuse detection and device-level security blocking. Not linked to hardware.

The KhmerCow admin web panel (app_web) does not use cookies. An administrator's
session is held in the browser's session storage (via encrypted local storage)
and is cleared when the browser tab is closed. It is essential to maintaining a
logged-in admin session, is not an advertising mechanism, and does not track
users across other websites.

We do not currently use third-party advertising trackers, cross-site tracking
cookies, or browser fingerprinting technologies.


---------------------------------------------------------------------------
9. PUSH NOTIFICATIONS
---------------------------------------------------------------------------

With your permission, we send push notifications via Firebase Cloud Messaging
(FCM). Notification types include:

  Buyers:
  - Order status updates (processing, shipped, delivered, cancelled)
  - Delivery confirmation alerts

  Vendors:
  - New order received
  - Order accepted or rejected updates
  - Payment confirmations (subscription and package fees)
  - Promotion package expiry reminders
  - Subscription plan expiry reminders
  - Store approval or rejection decisions
  - Account security alerts

  All users:
  - Security alerts (e.g., new login from unrecognized device)
  - Optional promotional messages and platform news, by push or email, only
    where you have opted in (Settings > Notification Settings > Promotions)

Your FCM device token is stored on our servers associated with your account.
It is removed when you log out, delete your account, or revoke notification
permission.

You may disable push notifications at any time via your device operating system
settings. Disabling push notifications does not affect transactional emails or
SMS messages (such as OTP codes) that are required for secure account operation.


---------------------------------------------------------------------------
10. INTERNATIONAL DATA TRANSFERS
---------------------------------------------------------------------------

KhmerCow relies on globally distributed cloud service providers. Your personal
data may be transferred to, and processed or stored on, servers located outside
the Kingdom of Cambodia, including in the United States (Google Cloud / Firebase,
AWS, Stripe), the European Union (Brevo), and other jurisdictions where our
service providers operate.

We ensure such transfers are accompanied by appropriate safeguards, including
reliance on the data protection commitments and security certifications of our
service providers:
  - Google: https://policies.google.com/privacy
  - Amazon Web Services: https://aws.amazon.com/privacy/
  - Stripe: https://stripe.com/privacy
  - Cloudinary: https://cloudinary.com/privacy
  - Twilio: https://www.twilio.com/en-us/legal/privacy

By using the Platform, you acknowledge that your data may be transferred and
processed internationally under these safeguards.


---------------------------------------------------------------------------
11. CHILDREN'S PRIVACY
---------------------------------------------------------------------------

The Platform is strictly intended for users who are 18 years of age or older.
We do not knowingly collect personal data from individuals under the age of 18.
If we become aware that a person under 18 has submitted personal data or created
an account, we will promptly delete that data and terminate the associated
account. If you believe a minor has registered or submitted data on the Platform,
please notify us immediately at info@khmercow.com.


---------------------------------------------------------------------------
12. CHANGES TO THIS POLICY
---------------------------------------------------------------------------

KhmerCow may update this Privacy Policy periodically to reflect changes in our
services, technology, legal requirements, or other operational factors. When we
make material changes, we will:

  - Update the "Last Updated" date at the top of this Policy.
  - Publish the updated Policy on our website (https://khmercow.com/).
  - Notify registered users via in-app notification, push notification,
    or email for significant changes.

Your continued use of the Platform after the revised Policy becomes effective
constitutes your acceptance of the changes. If you do not agree with an
updated Policy, you should discontinue use and may contact us to exercise
your data rights.


---------------------------------------------------------------------------
13. CONTACT US AND DATA DELETION REQUESTS
---------------------------------------------------------------------------

For privacy inquiries, data access requests, correction requests, deletion
requests, or any concern about how we handle your personal data:

  Email:         info@khmercow.com
  Website:       https://khmercow.com/
  Deletion page: https://khmercow.com/account-deletion
  Data request:  https://khmercow.com/data-request

We aim to respond to all privacy-related requests within 30 days of receipt.
Requests submitted via the in-app account deletion feature may be processed
more quickly.


---------------------------------------------------------------------------
(c) 2026 KhmerCow Marketplace. All rights reserved.
This Privacy Policy is effective as of April 3, 2026.
---------------------------------------------------------------------------
Home Terms of Use Support Request your data Delete your account

Contact: info@khmercow.com