Legal · Marigold & Marigold HRMS apps

Mobile App Privacy Policy

How the Marigold and Marigold HRMS mobile applications collect, use, store and protect your information.

Applies to: Marigold (Android com.marigoldjewel.app / iOS) and Marigold HRMS. Last updated: 22 August 2026. Effective: 22 August 2026.

1. Who we are

These applications are published by Marigold Jewelry Co. Ltd. (“Marigold”, “we”, “us”), 316,318 soi Rachadapisake 9, Rachadapisake Road, Daokanong, Thonburi, Bangkok 10600 Thailand. We are the data controller for the personal information described below. For any privacy question or request, contact admin@marigoldjewel.com.

2. Scope

Marigold is a business application used by our customers, sales partners and staff for jewellery catalogue browsing, orders, quotations, job tracking and internal ERP workflows. Marigold HRMS is an employee self-service application used by Marigold personnel and personnel of organisations that license our HRMS platform, for attendance, leave, payroll documents and internal communication. Both apps are access-controlled: they can only be used with credentials issued by Marigold or by your employer. They are not intended for children and we do not knowingly collect data from anyone under 16.

3. Information we collect

3.1 Information you or your organisation provides

  • Account & identity data — name, employee or customer code, company, designation, department, email address, mobile number, profile photo, and your login credentials.
  • Work records — in HRMS: attendance punches, shift and roster data, leave and permission requests, overtime, salary advance requests, payslips and tax documents, appraisals, and documents you upload. In Marigold: orders, quotations, job cards, stock and design records, approvals and comments you create.
  • Content you submit — photos, files, voice notes, chat messages, support tickets and helpdesk requests.

3.2 Information collected with your permission on the device

  • Camera & photo library — only when you choose to capture or attach an image (profile picture, attendance selfie, QR/tag scan, attachment on a request or job card).
  • Microphone — only while you record a voice note or a video.
  • Precise location — used while the app is in use to verify that an attendance punch, site visit or field activity took place inside an approved geofenced location. We do not track your location in the background and we do not build movement profiles outside these recorded events.
  • Face / biometric sign-in — where enabled, the app can verify your face or use your device fingerprint / Face ID to sign you in. Device biometrics (Face ID / fingerprint) never leave your device and are handled entirely by the operating system. Where face verification for attendance is enabled by your employer, the face image or template is stored on our servers solely to confirm identity for attendance, is not used for any other purpose, is not shared, and is deleted on request or when the account is closed.
  • Notifications — a push token (Firebase Cloud Messaging / Expo) so we can deliver approvals, alerts, announcements and chat messages.

3.3 Technical data

  • Device model, operating system version, app version, a device identifier used for session binding, IP address, timestamps, and error/diagnostic logs. We use this to keep the account secure and to fix crashes.

We do not collect payment card details in the apps, and we do not sell your personal information or share it with advertising networks or data brokers. The apps contain no third-party advertising SDKs.

4. Why we use it (legal bases)

  • To provide the service you or your employer signed up for — performance of a contract.
  • To verify attendance, location and identity for workforce and payroll purposes — legitimate interests of the employer and, where required, your consent (device permissions and biometrics are always opt-in and revocable in your device settings).
  • To keep accounts secure — login, device binding, and prevention of fraud and misuse.
  • To send operational notifications about your requests, approvals and messages.
  • To comply with legal, tax and employment obligations.

5. Sharing

Your information is visible to authorised users of your own organisation on a role and permission basis (for example your manager, HR and payroll staff, or the Marigold team handling your order). Beyond that we share only with:

  • Service providers who host or transmit data on our behalf — our hosting and storage providers, Google Firebase Cloud Messaging and Expo for push delivery, and email / SMS / WhatsApp gateways for notifications. They act on our instructions only.
  • Authorities where we are legally required to do so, and advisers or acquirers in a corporate transaction, subject to confidentiality.

Data may be processed on servers outside your country; where that happens we rely on appropriate safeguards and contractual protections.

6. Retention

Account, attendance, payroll and transaction records are retained for as long as the account is active and afterwards for the period required by employment, tax and accounting law. Diagnostic logs are kept for a short period (typically up to 12 months). Optional data such as face templates, attachments and push tokens is deleted when you withdraw permission, on request, or when the account is closed.

7. Security

Access requires authentication and is restricted by role. Traffic between the apps and our servers is encrypted in transit (HTTPS/TLS), credentials are stored hashed, sessions can be bound to a registered device, and administrative actions are logged. No system is perfectly secure, but we work to protect your data and to notify affected users and regulators of any breach as required by law.

8. Your rights and choices

  • Permissions — camera, photos, microphone, location, biometrics and notifications can each be granted or revoked at any time in your device settings. The rest of the app keeps working; only the related feature stops.
  • Access, correction, deletion, restriction, objection and portability — you may ask us for a copy of your data, to correct it, or to delete it. If you use the app through your employer, we will refer the request to them as the responsible party and assist them in answering it.
  • Account & data deletion — write to admin@marigoldjewel.com with the subject “App account deletion” from your registered email address, and we will delete your app account and the associated personal data within 30 days, except records we are legally required to keep (for example statutory payroll and tax records).
  • Withdraw consent — at any time, without affecting processing already carried out.

9. Changes

We will post any change to this policy on this page and update the “Last updated” date. Material changes will also be announced inside the apps.

10. Contact us

Marigold Jewelry Co. Ltd.
316,318 soi Rachadapisake 9, Rachadapisake Road, Daokanong, Thonburi, Bangkok 10600 Thailand
Privacy & data requests: admin@marigoldjewel.com
General enquiries: sales@marigoldjewel.com
Phone: +66817350594
WhatsApp: +1 (905) 921-8225
Hours: Mon - Fri: 9AM - 7PM

This page is the official privacy policy URL for the Marigold and Marigold HRMS mobile applications on the Apple App Store and Google Play: https://marigoldjewel.com/app-privacy-policy

Need more help?

Our concierge team is available seven days a week.

Contact Us