Privacy Policy

Last updated 2026-09-08

This policy covers SentiDawn and every product we operate. Each product then tells you what it does with data of its own, inside the product, before you use it.

On this page ▾

Who we are

SentiDawn builds and operates software products — TrainMate, FlowPay and SpendTrail among them — and this website. In this statement “SentiDawn”, “we” and “us” mean the operator of those products, and “you” means anyone who signs in to one of them or visits this site.

It is written with regard to Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”). Questions about it, and any request under Your rights below, go to [email protected].

SentiDawn’s role

Most of our products sit between two sides of an arrangement that already exists in the real world: someone receiving a service and someone providing it — a member and their trainer, a business and the people who work for it. The product’s job is to keep both sides looking at the same record.

The limits of that role are:

  • We are not the provider of the service itself. The training, the work performed, the advice given — those come from the other side of your arrangement, not from us.
  • We are not a party to the agreement between you and them. What was charged, what was cancelled, and whether the service was any good are between the two of you.
  • We do not receive, hold or move money. Where a product records a payment, it is recording that a payment happened somewhere else.

Which means the data inside a product is of two different kinds:

  • Data we decide about. Your sign-in identity, your account and roles, the record of what you accepted and when, and our own operational logs. For these, SentiDawn is the one who determines why they are held.
  • Data the other side decides about. What a service provider chooses to record about their own customers inside a product — sessions, notes, amounts, attachments. They decide what goes in and why; we store and process it so that the product works.

If you want something in the second kind changed, the provider who recorded it is the right person to ask first. Write to us anyway and we will tell you who that is and pass the request along.

This statement and each product’s notice

This statement sets out the principles that apply across SentiDawn and every product we operate.

Each product then has a notice of its own, because each one collects different things: TrainMate knows about training sessions, FlowPay about timesheets and settlement, SpendTrail about the receipts you upload. Those notices are not published here. They are shown to you inside the product, the first time you use it and again whenever a new version is issued, and you accept them there — at the moment they actually apply to you. We keep one central record of what you have accepted, so a document shared by several products is accepted once.

Where a product’s notice is more specific than this statement, it governs the data in that product. Where it is silent, this statement applies. Nothing in a product notice takes away a right this statement gives you.

Information we collect

Across every product:

  • Sign-in identity. You sign in with Google, which gives us your name, your email address and the URL of your profile picture. Your Google password never reaches us. The picture is displayed from Google, not copied and stored by us. We ask for nothing beyond basic profile information unless a product tells you otherwise, on its own notice, before you agree.
  • Your account and its roles. Which products you can open, what role you hold in each, and which other accounts you are linked to.
  • What you have accepted. Which document, which version of it, which product it belonged to, and when you accepted it. This is the evidence that your consent existed; without it we could not honour it or show it back to you.
  • The records you and the other side put into a product. Itemised in that product’s own notice, not here.
  • Optional information. Where a product invites something extra — a note, an amount, an attachment — it is optional and marked as such, and leaving it blank does not stop the product working.
  • Operational logs. Sign-ins, errors and system events, kept so we can keep the service secure and work out what went wrong.

Why we use it

  • To run the product you signed in to, and to show each side the record it is entitled to see.
  • To know who you are, and to enforce what your role may and may not reach.
  • To keep — and to be able to show you — what you accepted and when.
  • To keep the service secure, to diagnose faults, and to recover from them.
  • To write to you about the service itself: a change to these documents, an outage, something that needs your attention.

Our commitments about your data are: we do not use your data for advertising, we do not sell it, and we do not combine data across products to profile you. Two SentiDawn products knowing your email address is not the same as them sharing what you did inside them — see the next section.

Those three are commitments, not a description of current practice. If any of them ever changed it would be a material change. Updating this page alone would not be enough: you would be asked to accept the new version inside the product, as described under Changes to this statement.

Who can see what

  • You — your own records, and the part of the arrangement the product is built to show you.
  • The other side of your arrangement — your trainer, your client, whoever it is in that product — sees what the product shows them about the work between the two of you, and nothing about anyone else’s.
  • Other customers of the same provider do not see your data.
  • Other SentiDawn products do not see each other’s data. Your sign-in identity and the record of what you accepted are shared across products deliberately, so that you sign in once and accept a shared document once. The records inside a product stay inside it.
  • We see what operating the service requires — supporting an account, restoring data, investigating a fault or a report of abuse. Access is limited to these purposes.

We keep one central record of what each person has accepted, rather than leaving each product to remember separately. The process is described below.

  • When you first open a product, and whenever a document you already accepted is reissued in a new version, the product shows you what you are being asked to accept, and you accept it there.
  • Some consents are required — without them the product cannot do its job, and you will not be able to continue into it.
  • Some consents are optional — decline, and the product runs with the feature that needed it switched off. Nothing else changes.
  • Some consents are shared across products — accept once, and every product that relies on that document sees it as accepted.
  • You can withdraw a consent at any time by writing to us. Withdrawing an optional consent turns that feature off. Withdrawing a required one means we can no longer provide that product to you, and we will tell you what happens to the records already in it before anything is removed.

How long we keep it

  • Your account and identity data — for as long as the account exists, and until you ask us to delete it.
  • Records inside a product — by that product’s own rule, published in its notice. TrainMate, for example, keeps the history of a trainer–member pairing viewable for 90 days after the pairing is deactivated.
  • Consent records — kept for 10 years after the relationship ends, whether it ended because you asked us to delete your account or for any other reason. They outlive the account on purpose: they are the evidence that your consent existed, and destroying them early would leave neither of us able to show what was agreed.
  • Operational logs — kept for 1 year.
  • Where the law requires us to keep something for longer, we keep it, and only it.

Sharing with others

  • We do not sell your personal data, and we do not share it with anyone for their marketing.
  • It is processed on the hosting and infrastructure we use to run the service, as far as running it requires and no further.
  • Google sees your sign-in, because you sign in with Google; what Google does with that is covered by Google’s own privacy policy. You can disconnect any SentiDawn product from your Google account at myaccount.google.com/permissions.
  • We disclose data where the law, or a lawful order of a competent authority, requires it.

Security

You sign in through Google. We do not receive or store your Google password. Every product enforces access by role and the visibility limits described above. Data in transit is encrypted, and products are kept separate from one another.

No system is perfectly secure. Keep your Google account safe, because someone who can access it may also be able to sign in to your SentiDawn account.

Your rights

Under the PDPA you may:

  • ask what personal data of yours we hold, and ask for a copy of it;
  • ask us to correct it where it is wrong or out of date;
  • ask us to delete it, subject to anything the law requires us to keep;
  • withdraw a consent you gave, as described above;
  • object to, or ask us to restrict, a particular use of it;
  • complain to the Personal Data Protection Committee if you believe we have got it wrong.

Write to [email protected]. We answer within 30 days. If your request concerns records a service provider entered about you, we will tell you who that provider is and pass the request on to them.

The following exception applies to acceptance records: a deletion request does not erase the record of what you accepted. That record is what proves your consent was asked for and given, so it is kept for the period in How long we keep it and then destroyed. Everything else goes.

Cookies and sessions

A product sets one cookie, to keep you signed in. It is not a tracking cookie and not an advertising cookie, and we run nothing that follows you around after you leave. This website sets no cookies at all.

Age

SentiDawn products are for adults. They are not offered to anyone under 20 years of age — the age of legal majority in Thailand — and we do not knowingly collect the personal data of a minor.

We do not verify anyone’s age with documents. Instead, accepting a product’s terms is your confirmation that you are 20 or older, and where an account is created for you by the other side of an arrangement, that confirmation is yours to give before the account becomes usable.

If we learn that an account belongs to a minor we close it and delete the personal data in it, keeping only what the section above requires. If you believe a minor’s data has reached us, write to [email protected] and we will deal with it.

Changes to this statement

We update this statement when what we do changes. The date at the top of the page belongs to the current text and is always the version in force.

If a change materially affects you, we notify you inside the product and ask you to accept the new version, the same way you accepted the first one.

Contact

SentiDawn · [email protected]. This statement is governed by the laws of the Kingdom of Thailand.

Privacy Policy · SentiDawn