Pammo ← Back to Legal Center
ดูฉบับภาษาไทย →

Effective 15 June 2026 · Updated 18 May 2026

PAMMO — COOKIE NOTICE

Version 1 — Publication-Ready Pending Final Review Last Updated: 2026-05-18 Effective Date: 15 June 2026

This Cookie Notice explains how AEDOWON CO., LTD and AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D), operating Pammo (together, "we", "us"), use cookies, local storage, pixels, SDKs, fingerprinting, and similar tracking technologies (collectively, "Cookies") when you access or use the Pammo website (pammo.co) and the Service.

This Notice supplements our Privacy Notice and is provided in compliance with:


1. WHAT COOKIES ARE

Cookies are small text files placed on your device when you visit a website. They allow the website to recognize your device and remember information about your visit (e.g., language preference, login state). "Cookie" in this Notice also covers:


2. CATEGORIES OF COOKIES WE USE

2.1 Strictly Necessary (Always On — No Consent Required)

Required for the Service to function. Cannot be disabled.

Cookie Provider Duration Purpose
pammo_session Pammo (first-party) Session Maintain your login session
pammo_csrf Pammo Session Cross-site request forgery protection
pammo_consent Pammo 12 months Remember your cookie-consent choices
pammo_locale Pammo 12 months Remember your language preference (Thai / English)
pammo_route Pammo 12 months Remember your TH / International contracting-entity route per Main T&C §0
sb-* Supabase Session — 7 days Authentication session (Supabase Auth)
__vercel_* Vercel Session Edge routing, deployment
cf_* Cloudflare Session — 30 days DDoS protection, bot mitigation
omise_* (TH Route at payment) Opn Payments Co., Ltd. (Omise) Session or as disclosed by checkout provider Process payment, fraud checks, 3-D Secure authentication on Thai cards
polar_* (International Route at payment) Polar Software, Inc. (Merchant of Record) Session or as disclosed by checkout provider Process payment, MoR tax, fraud checks, 3-D Secure or equivalent authentication

2.2 Analytics (Consent Required — First-Party Only)

Analytics cookies help us understand how Users interact with the Service. Pammo operates product analytics in-house (first-party Supabase + Vercel — see Pammo-Sub-Processor-List-V1 §5); no third-party product-analytics Sub-Processor is engaged at launch. Analytics cookies are loaded only after you consent via our cookie banner.

Cookie Provider Duration Purpose
pammo_analytics_* Pammo (first-party) 12 months Aggregate product analytics: event tracking, funnel, retention — first-party only

Omise and Polar billing analytics are server-side only and do not set browser cookies on End Users.

2.3 Retargeting / Advertising Networks (Per-Network Consent Required)

Where you have opted in (via Main T&C §13B) to share data with advertising networks for retargeting.

Cookie / Pixel Provider Duration Purpose
_fbp / Meta Pixel Meta 90 days Facebook / Instagram retargeting
_gcl_* / IDE Google 13 months Google Ads retargeting
_ttp / TikTok Pixel TikTok 13 months TikTok Ads retargeting
_line_oa_* LINE 12 months LINE Ads retargeting

Per-network granularity. You may consent to specific networks individually via the cookie banner or Account → Privacy → Ad-Network Sharing. Refusing one network does not refuse others.

2.4 FGF / Affiliate / Creator Attribution (Consent Required — Non-Essential)

The 60-day FGF / Affiliate / Creator attribution cookie is classified as non-essential because it serves the Inviter's / Affiliate's / Creator's commission rather than your primary use of the Service. Cookie duration is aligned at 60 days across all three programs per Pammo-Program-Rules-V1 §3.4, §4.5, §5.6, and Pammo-Creator-Program-V1 §3.2 / §6.1 V1.2 cookie-alignment.

Cookie Provider Duration Purpose
pammo_fgf_ref Pammo (first-party) 60 days Track FGF referral attribution
pammo_aff_ref Pammo (first-party) 60 days Track Affiliate referral attribution
pammo_cr_ref Pammo (first-party) 60 days Track Creator referral attribution

If you withhold consent for attribution cookies, attribution falls back to login-based identifiers (account ID, email at signup, payment-method hash) within the same 60-day window — a privacy-preserving fingerprint fallback. The Inviter / Affiliate / Creator who referred you can still be credited via login-time matching, but no cookie is set on your device.

2.5 Preferences (Consent Required — Optional)

Cookie Provider Duration Purpose
pammo_theme Pammo 12 months Light / dark mode preference
pammo_dashboard_layout Pammo 12 months Dashboard widget arrangement
pammo_listing_view Pammo 12 months Listing-Hub default view (grid / list / map)

3. HOW WE GET YOUR CONSENT

3.1 Cookie Banner

When you first visit pammo.co, a cookie banner is displayed that allows you to:

Strictly necessary cookies are set without consent.

3.2 Landing-Page Banner for Referral Visits

When you arrive at the Service via an FGF / Affiliate / Creator referral link, the cookie banner is displayed before the attribution cookie is set on your device. The attribution cookie is set only after you consent. If you reject, the login-fallback attribution under §2.4 applies.

3.3 Per-Network Sub-Checkboxes (Advertising Networks)

For advertising-network cookies / pixels, consent is collected on a per-network basis (separate sub-checkbox per network — Meta, Google, TikTok, LINE, others).

3.4 Children

Where the User is under the local digital-consent age, no non-essential cookies are set without verified parental consent.


4. HOW TO CHANGE OR WITHDRAW YOUR CONSENT

You may change your cookie preferences at any time:

(a) Via the in-app cookie preference center: Account → Privacy → Cookie Preferences (one-click rejection per category)

(b) Via your browser settings: Most browsers allow you to refuse / delete cookies. Note that disabling strictly necessary cookies will break Service functionality (payment, login, route detection).

(c) Via "Do Not Track" signals: We honor Global Privacy Control (GPC) and "Do Not Track" headers where legally required, treating them as opt-out signals for analytics, advertising, and attribution cookies.

Withdrawing consent does not affect cookies set before withdrawal — those will be deleted at their normal expiry or when you clear your browser. To delete cookies already set, use your browser's "clear cookies" function.


5. THIRD-PARTY COOKIES

Some cookies above are set by third parties (Google, Meta, TikTok, LINE, Cloudflare, Omise, Polar) when you consent to their use. These third parties have their own privacy and cookie policies, which we link in our Sub-Processor List. We do not control these third parties' privacy practices.


6. DO-NOT-TRACK AND GLOBAL PRIVACY CONTROL

We honor:

When we detect these signals, we treat them as withdrawal of consent for non-essential cookies.


7. RETENTION

Cookie durations are listed in §2 above. After expiry, cookies are automatically deleted from your device. Server-side records of consent (pammo_consent) are retained for duration of consent + 24 months post-withdrawal per Pammo-Privacy-Notice-V1 §6.


8. CHANGES TO THIS NOTICE

We may update this Cookie Notice from time to time. The "Last Updated" date reflects the most recent change. Material changes are notified by email and in-app banner.


9. CONTACT

DPO: dpo@pammo.co Privacy Inquiries: privacy@pammo.co Singapore registered office: AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D), 8 TEMASEK BOULEVARD, #17-02A, SUNTEC TOWER THREE, SINGAPORE 038988 Thailand registered office: AEDOWON CO., LTD, 250/207 SOI BUDDHAMONDON SAI 2 SOI 32, SALATHAMMASOP, TAWEWATTANA, BANGKOK 10170, THAILAND


CONFIRMED STACK (2026-05-18)

Hosting / CDN: Supabase + Vercel + Cloudflare ✅ Payment / dual-route: Omise (TH Route) + Polar.sh (International Route MoR) ✅ Email: Resend (transactional + transport for in-house marketing emails) ✅ Product analytics: Pammo first-party (Supabase + Vercel) — no third-party analytics vendor at launch ✅ Attribution cookie: Pammo first-party, 60-day window unified across FGF + Affiliate + Creator (cookie alignment per V1.2 Creator update) ✅ Cookie banner & GPC honoring: in place per §3 / §6

ℹ️ Mobile app: Pammo has no native iOS / Android app at launch. This Notice will be updated to add mobile-SDK cookies if / when native apps are released.


END OF PAMMO COOKIE NOTICE — V1 (PUBLICATION-READY PENDING FINAL REVIEW) Last Updated: 2026-05-18