🔒 Privacy Policy

Last updated: March 24, 2026

1. Introduction

Welcome to Ratana Store ("we," "our," or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website ratanastore.com and use our services.

By using our website, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Personal Information

When you create an account or make a purchase, we may collect:

  • Name and username
  • Email address
  • Phone number (optional)
  • Profile photo
  • Game account IDs (for top-up delivery)
  • Payment transaction information

OAuth Account Information

If you sign in with Google, Discord, Facebook, or TikTok, we receive your name, email, and profile picture from those services. We do not access your contacts, posts, or other account data.

Automatically Collected Information

  • IP address (for security and fraud prevention)
  • Browser type and version
  • Pages visited and time spent
  • Device information

3. How We Use Your Information

We use the information we collect to:

  • Process your orders and deliver game top-ups
  • Create and manage your account
  • Send order confirmations and updates
  • Send password reset and verification emails
  • Prevent fraud and unauthorized access
  • Improve our website and services
  • Respond to your inquiries and support requests

4. Payment Information

We accept payments via KHQR, ABA Pay, Wing, and other local methods. We do not store your bank account details, card numbers, or Bakong wallet information on our servers. Payment processing is handled by third-party providers who comply with industry security standards.

5. Data Sharing

We do not sell your personal information. We may share your data with:

  • Payment providers — to process transactions
  • Game platforms — to deliver top-ups (e.g., game ID, package selected)
  • Email service (Resend) — to send transactional emails
  • Law enforcement — if required by law or to protect our rights

6. Cookies & Sessions

We use essential cookies to keep you signed in and maintain your session. We do not use advertising or tracking cookies. Session cookies are set by NextAuth.js for authentication purposes only.

7. Data Security

We implement appropriate security measures to protect your personal information, including:

  • Encrypted connections (HTTPS/SSL)
  • Hashed passwords (bcrypt)
  • Rate limiting and IP-based security
  • JWT-based authentication tokens
  • Account lockout after failed login attempts

While we strive to protect your data, no method of transmission over the Internet is 100% secure.

8. Data Retention

We retain your account information as long as your account is active. Order history is kept for record-keeping and dispute resolution. You may request deletion of your account and associated data by contacting us.

9. Your Rights

You have the right to:

  • Access your personal information
  • Update or correct your information via your profile page
  • Disconnect linked social accounts (Google, Discord, Facebook, TikTok)
  • Request deletion of your account
  • Opt out of non-essential communications

10. Children's Privacy

Our services are not intended for users under the age of 13. We do not knowingly collect personal information from children. If we discover that a child under 13 has provided us with personal data, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us: