This Privacy Policy (the "Policy") sets out the basic principles for personal data handling on GearBid (the "Service") operated by Advanced Civil Construction & Engineering Co., Ltd. (the "Company"), and explains how you can exercise your rights. The Policy is based primarily on Thailand's Personal Data Protection Act B.E. 2562 / 2019 (the "PDPA"). We have put in place the following standards and procedures to handle your personal data lawfully and transparently.
This Policy applies across all touchpoints the Company provides — the mobile web, the PC web, in-app notifications, LINE integration channels, and customer support channels. You can review this Policy and choose whether to consent within the required scope when you sign up or first use the Service. Terms not defined here follow the definitions in the Terms of Service, Thai Civil Code, and the PDPA.
This Policy applies continuously from the moment you first use the Service until the statutory retention period ends after your account is closed. If the Company's policy changes or the law is amended, the Policy will be updated after prior notice under Section 13. If you find it hard to understand any part of this Policy, you can contact the DPO for an explanation, and the Company is obliged to explain it in plain language.
The Company runs this Policy so that it fits with the PDPA and international personal data protection principles: Transparency, Purpose Limitation, Data Minimisation, Accuracy, Storage Limitation, Integrity and Confidentiality, and Accountability. These principles are not just statements; they are reflected in every stage of actual service design, operations, outsourcing contracts, and employee training.
1. Overview and DPO Contact
GearBid is a reverse-auction brokerage platform connecting construction equipment rental demand and supply for the Thai market (Bangkok, Chonburi, and others). In delivering the Service, the Company collects, uses, stores, shares, and destroys your personal data and takes responsibility for all such processing. The Company holds the status of Data Controller under the PDPA. For some activities (payment processing, cloud hosting, notification delivery, and others), external vendors are involved as Data Processors.
In line with PDPA §41, the Company has appointed a Data Protection Officer (the "DPO"). The DPO oversees checks on the lawfulness of personal data processing, handles data subject rights requests, responds to personal data breaches, trains internal staff, and cooperates with the regulator.
- Data Protection Officer (DPO): Eun Sung Jeong (James)
- Contact email: contact@gearbid.io
- Contact phone: +66-(0)81-378-0115
- Company address: No. 68 Bangna-Trad 23, Bangna Nuea, Bangna, Bangkok 10260
You can contact the DPO at the details above at any time with questions about this Policy, our current personal data handling, or how to exercise your rights. We will respond in good faith within the statutory period after receiving your request. The Service is governed by Kingdom of Thailand, and personal data disputes fall under the jurisdiction of Courts of Bangkok, Thailand.
2. Categories of Personal Data Collected
The Company collects only the minimum personal data required in proportion to the purpose. The items collected vary by user type (Client, Supplier, Admin) and by feature used. The detailed items are as follows.
| Category | Items | Example / When collected |
|---|---|---|
| Sign-up information | Name, phone number, phone verification record | OTP verification at sign-up |
| Profile | Nickname, profile image, company information, business registration number, business address | When completing the profile after sign-up |
| Business verification documents | Business registration document (PP20, DBD, etc.) images/files, OCR auto-extracted information (company name, tax ID, address) | In-app upload during company/Supplier verification |
| Equipment information (Supplier) | Equipment type, model, year of manufacture, quantity, equipment photos, maintenance condition | When the Supplier registers equipment |
| RFQ information (Client) | Equipment request specifications, quantity, rental period, budget range | When the Client registers an RFQ |
| Bid and contract information | Bid amount, selection history, e-contract signature image, contract PDF | When a bid or contract is concluded |
| Payment information | Payment method type, payment authorisation number, payment date, tax invoice information | At down payment and settlement |
| LINE integration | LINE user ID, LINE access token (for login) | At LINE account integration |
| Google login | Google account identifier (sub), email | When logging in with a Google account |
| Device and log | IP address, User Agent, access timestamp, session ID, browser cookie identifier | Automatically collected while you use the Service |
| Location information | RFQ site coordinates (latitude, longitude), equipment deployment site address | At RFQ registration and contract conclusion |
| Customer support records | Inquiry content, email address, attachments, call history | At 1:1 inquiry and phone inquiry |
| Credit and reputation information | Review content and star rating, Credit Score, penalty record | At mutual review after a transaction |
The Company does not as a rule collect sensitive personal data (such as race, religion, political opinions, sexual orientation, health information, or biometric data). Where required by law (for example, identity verification documents), we only handle them in a limited way after obtaining separate explicit consent.
Some items above may not be collected depending on how you use the Service. For example, RFQ-related items are not collected from users who act only as Suppliers, and equipment inventory items are not collected from users who act only as Clients. We provide specific notice of the items collected on each input form and consent screen.
We regularly review the items we collect and remove or anonymise those that are no longer needed. Information that is not reasonable to keep long term — such as old logs not directly used for Credit Score calculation — is destroyed or transformed into an unrecoverable form as soon as its retention period expires.
3. Collection Methods
We collect personal data in the following ways. Each collection method operates in a form that is recognisable to you, following the notification duty under PDPA §23.
- Direct input by the user: Information you enter or upload during sign-up, profile completion, equipment registration, RFQ registration, bid submission, e-contract signing, customer support inquiries, and other interactions with the Service. For each field, we clearly mark required and optional items, and you can refuse to fill in optional fields.
- Automatic collection during use: Device and log information, cookie identifiers, and usage patterns (page navigation, feature usage frequency, etc.) are collected automatically while you use the Service. For the specific purposes of cookies and how to control them, see the Cookies Policy.
- Social login integration (LINE / Google): If you choose social login, the information needed for login is transmitted through the LINE or Google official API — the LINE user ID and login access token for LINE, and the account identifier (sub) and email for Google. We do not collect information beyond what is needed for login (such as your friend list or timeline).
- In-app document upload and OCR auto-extraction: When you upload a business registration document (PP20, DBD, etc.) in the app for company/Supplier verification, an external OCR service (Google Cloud Vision) automatically extracts and verifies information such as company name, tax ID, and address. The uploaded document image is transmitted to the OCR service for extraction and is not retained separately after processing. Separately, the contract down payment and other payments are handled by bank transfer with manual confirmation by our operations team; no external payment gateway (PG) is integrated.
- Offline operation channels: In the initial MVP stage, a Wizard-of-Oz approach may be used in which the Company's operations team enters information on behalf of a Client or Supplier. Even then, only information collected with the user's consent is entered into the system.
- Paper and email channels: In addition to in-app upload, official documents between the Company and you (contracts, powers of attorney, etc.) may exceptionally be collected by paper or email. Originals are scanned and stored electronically, or where the law requires originals to be kept, they are stored separately in a secure manner.
On collection, we clearly tell you who the collector is, the items collected, the purpose, the legal basis, your rights, and the effect of refusal. You have the right not to agree to the notified items. If you refuse required items, use of the relevant feature or part of the Service may be limited, but no adverse treatment follows.
4. Purposes of Processing
We only process personal data for the following purposes. When a purpose is achieved or consent is withdrawn, the related information is promptly destroyed or anonymised.
- Sign-up and identity verification: Phone OTP verification, prevention of duplicate sign-ups, and verification of business credentials by OCR matching of business registration documents.
- Service delivery (matching and contract formation): RFQ registration, Supplier notifications, bid collection, contract conclusion, and equipment mobilisation and return schedule management.
- Credit Score calculation and reputation management: Aggregating mutual reviews, reflecting transaction performance, detecting fraud and misconduct, and deciding whether to restrict bidding.
- Payment processing and settlement: Collecting the down payment (10%), settling payments to Suppliers, processing refunds, issuing tax invoices, and keeping accounting records.
- Notifications: Transaction progress notifications, bid deadline alerts, settlement notifications, and security alerts delivered through email, SMS, and in-app push.
- Legal obligations: Keeping transaction records under Thai tax law, identity verification under anti-corruption and anti-money-laundering laws, and responding to lawful requests from courts and investigative authorities.
- Customer support and dispute resolution: Handling 1:1 inquiries, mediating transaction disputes, running refund or compensation procedures, and keeping internal records to prevent recurrence.
- Service improvement and statistics: Usage pattern analysis, feature usage frequency, conversion funnel analysis, A/B tests, and bug-report collection. We use the product-analytics tool (PostHog), and statistics are, as a rule, processed into an unidentifiable form (anonymised or pseudonymised) for use.
- Security and fraud prevention: Detecting unusual sign-ins, preventing misuse of multiple accounts, detecting collusive bids, and analysing logs for vulnerability checks.
- Marketing (only with separate consent): Information about new features, promotions, and events. Marketing-related processing is limited to users who have given separate consent on the Marketing Communication Consent page, and unsubscribing is always possible.
- Internal risk management: Using signals such as drops in Credit Score, repeated contract cancellations, and dispute history together to manage platform-wide risk. Where an automated decision is involved in risk management, you have the right under PDPA §30(4) to object to that decision and request a human review.
- Audit and internal control: Used for the Company's internal financial audit, compliance checks, conflict-of-interest management, and responding to audit authorities.
If we need to use personal data for purposes outside this list, we will obtain separate additional consent from you, clearly describing the scope, period, and method of the additional use. Once a purpose has been achieved, we no longer keep the relevant personal data; where statutory retention applies, we store it separately.
5. Legal Basis (PDPA §24)
PDPA §24 lists the legal bases for processing personal data. For each processing activity we identify one or more of the bases below and apply it. The legal basis varies by purpose and by item.
- Consent: Applies to processing activities you have explicitly chosen, such as marketing, optional cookies (analytics and advertising), and the limited collection of sensitive data. You may withdraw consent at any time; processing before withdrawal remains lawful.
- Contract: Applies to processing needed to perform the contract between you and the Company (sign-up, agreement to the Terms of Service, the sublease contract, and similar). This is the main basis for handling sign-up information and RFQ, bid, contract, and payment information. Refusing this processing may restrict use of the Service itself.
- Legal obligation: Applies to processing required for the Company to comply with related laws, such as the Thai tax law (minimum 5-year retention of transaction records), anti-corruption and anti-money-laundering laws, labour law, consumer protection law, and electronic commerce law. Response to lawful warrants or investigation requests from authorities also falls under this basis.
- Legitimate interest: Applies where the Company's or a third party's legitimate interest outweighs your rights and freedoms. Credit Score calculation, fraud and misconduct prevention, service security logs, platform abuse prevention, and basic analytics statistics fall here. We run a Legitimate Interest Assessment internally to balance the legitimate interest against your rights.
- Vital interest / Public interest: These generally do not apply in ordinary platform operations. They may apply in very limited exceptional situations where we must use contact or location information to protect your life or physical safety in an emergency.
To present the legal basis to you transparently, on each consent screen and form the Company sets out the basis for the processing activity and the effect of refusal.
More than one legal basis can apply to a single item of personal data at the same time. For example, a phone number can be processed based on both contract performance (service delivery) and legitimate interest (fraud prevention), so even if you withdraw consent, processing under a remaining legal basis may continue. We explain this overlap clearly.
If we need to change a legal basis (for example, moving a processing activity from consent to legitimate interest), we will notify you in advance of the impact on you and offer the opportunity to re-consent or object where needed.
6. Third-Party Sharing
As a rule, we do not share your personal data externally. Where sharing with a third party is unavoidable for service delivery or is required by law, we share only the minimum needed. The main categories of recipients are email and SMS notification providers, cloud infrastructure providers, document OCR services, product analytics services, social login providers, and accounting and tax service providers. The contract down payment and other payments are handled by bank transfer and are not shared with any external payment gateway (PG).
You can check the details of each recipient, the items shared, the purpose, and the retention period in the Third-Party Information Sharing Consent. Sharings that need separate consent are handled on that screen so that you can selectively agree. Where sharing is mandatory under law (court warrant, lawful request from an investigating authority, etc.), we may share without separate consent, and we record the fact and basis for sharing in our internal log.
When sharing personal data with a third party, we limit the scope to the minimum needed for the purpose, and contractually require the recipient to maintain security duties, to not use the data outside the purpose, and to not share it onwards.
Third-party sharing and outsourcing of processing are different. Outsourcing means an external vendor processes personal data under the Company's instructions (for example, cloud hosting, email sending services). In that case the vendor is a Processor and may not process the data outside the scope of the Company's instructions. Third-party sharing, by contrast, is when the recipient processes personal data for its own purpose and at its own responsibility (for example, when a tax service provider performs accounting as part of its own professional work). In that case the recipient is a separate Controller and holds its own legal responsibility.
You can ask the DPO for a list of recipients your personal data has been shared with to date and the sharing dates. Where a legitimate reason applies, you can ask the Company to stop sharing with a specific recipient. We will accommodate your request as far as possible, where this does not conflict with legal or contractual obligations.
7. Cross-border Transfer
We run the Service's core infrastructure (servers and databases) in the AWS Thailand (Bangkok, ap-southeast-7) region, so user data is in principle kept within Thailand. However, some functions — email delivery, SMS delivery, social login, and product analytics — use servers outside Thailand, so that data processing constitutes a Cross-border transfer as defined in PDPA §28.
We use the following methods to secure the adequate level of protection required by PDPA §28:
- Transfer to a country with an adequate level of protection: We check whether the receiving country is recognised by the PDPC (Personal Data Protection Committee) as having an adequate level of personal data protection.
- Standard Contractual Clauses: Where the data is transferred to a business in a country without a recognised adequate level of protection, we sign Standard Contractual Clauses or an equivalent contract with the recipient to impose an equivalent level of protection.
- Explicit consent from the user: Where neither of the two bases above applies, we tell you the receiving country, the purpose of the transfer, the items transferred, and the risks, and only transfer after obtaining your separate consent.
- Encryption and access control: We apply TLS 1.2 or higher for transfer encryption, and at the storage stage we keep at-rest encryption and strict access control.
Our main current cross-border recipients are email delivery (Resend), SMS delivery (AWS Singapore region), document OCR (Google Cloud Vision), product analytics (PostHog, United States), and social login (LINE, Google). You can find the specific list of recipients and change history in the Third-Party Information Sharing Consent.
We periodically reassess the scope, recipients, and risk level of cross-border transfers. If changes in the law of a receiving country (for example, granting broad government access rights) risk a serious impact on user rights, we may stop transfers to that country or put in place additional protective measures. If needed, we will notify you of the impact in advance.
If you have further questions or objections about cross-border transfers, you can contact the DPO. We will provide information on transfer facts, recipients, purposes, and protective measures in good faith.
8. Retention Periods
We retain personal data only for the period needed to achieve the purpose. Once the period expires, we promptly destroy or anonymise it. Information subject to a statutory retention obligation is securely stored separately for the required period.
| Category | Retention | Basis |
|---|---|---|
| Account information | Until account closure | Contract |
| Transaction records (RFQ, contract, payment history) | 5 years after transaction completion | Retention obligation under Thai tax law |
| E-contract originals and signatures | 10 years after contract ends | Thai Civil Code and electronic transactions law |
| Dispute-related records | 3 years after dispute ends | Legitimate interest (evidence preservation) |
| Access logs, security logs | 90 days from collection | Legitimate interest (security) |
| Customer support inquiry records | 3 years after inquiry ends | Legitimate interest (preventing recurrence) |
| Marketing consent and receipt history | Until consent is withdrawn | Consent |
| Cookies and tracking identifiers | Period set in the Cookies Policy | Consent / Legitimate interest |
| Reviews and Credit Score source records | While the account is active | Legitimate interest (reputation management) |
When an account closure request is received, we destroy the personal data within 30 days, other than information we are required to retain by law. Destruction is carried out by unrecoverable methods for electronic files (permanent deletion, destruction of encryption keys, and similar) and by shredding or incineration for paper printouts.
Even after the retention period ends, information whose identifiability has been removed through anonymisation or pseudonymisation may still be used for statistical or research purposes; such data may fall outside the scope of the PDPA. We regularly check the robustness of anonymisation so that re-identification risks do not arise.
You can ask for a specific explanation of retention periods or for early destruction of specific items. We honour such requests as long as they do not conflict with a statutory retention obligation. Once destruction is complete, we notify you of the fact and the date.
9. Rights of the Data Subject (PDPA §30-34)
You can freely exercise the data subject rights guaranteed by the PDPA. Once we receive a rights request, we will notify you of the outcome within the statutory period of 30 days, which may be reasonably extended up to 60 days. When extended, we will tell you the reason for the extension.
- Right of access: You can ask what personal data the Company processes about you and how. After confirming your identity, we provide information on the items processed, the purposes, recipients, and similar. For repeated or excessive requests, a reasonable fee may apply.
- Right to rectification: You can ask for your personal data to be corrected or supplemented if it is inaccurate or out of date. Information you can edit directly on the profile screen can be updated by you. For other items, contact the DPO.
- Right to erasure / be forgotten: Where the legal basis has ceased, you have withdrawn consent, or unlawful processing is confirmed, you can ask for your personal data to be erased. We delete items except where a statutory retention obligation remains.
- Right to restriction of processing: If you object to the accuracy of processing, or while a review of the processing is pending, you can ask us to temporarily restrict processing of the personal data.
- Right to object: You can at any time object to specific processing activities based on legitimate interest (for example, marketing, general analytics) or direct marketing. Once an objection is received, we stop the relevant processing unless we have an overriding reason under the law.
- Right to data portability: For personal data processed based on consent or contract performance and collected by automated means, you can ask to receive information you provided in a structured, machine-readable format (such as JSON or CSV), or to have it transferred to a third party.
- Right to withdraw consent: For items processed on the basis of consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal; after withdrawal, the processing stops.
- Right to lodge a complaint: If you have an objection to our personal data handling, you can file a complaint directly with the PDPC (Personal Data Protection Committee). For PDPC filing procedures, see Section 14.
To exercise your rights, send your request and identity verification information to contact@gearbid.io or submit it through in-app 1:1 inquiry. We will respond with the outcome (approval, reason for rejection, request for further documents, etc.) within 30 days of receipt. If your request is rejected, you have the right to ask the PDPC for review.
When you exercise your rights, we verify, by reasonable means, that you are the data subject or an authorised representative. This check exists to prevent harm from third parties trying to access or delete someone else's personal data. Information used for verification is not used for any other purpose and is destroyed immediately after verification. If the verification process imposes an unreasonable burden, you can ask for alternative verification means.
Exercising your rights is free of charge as a rule. However, where the same request is repeated within a reasonable period or is clearly excessive (for example, dozens of access requests for the same information), we may charge a reasonable fee or refuse the request under the PDPA. If we refuse, we give the reason in writing.
10. Cookies and Tracking
We use cookies and similar tracking technologies to improve service performance, keep you signed in, offer personalised features, and analyse usage patterns. Cookies fall into four categories by function and purpose.
- Strictly necessary: Cookies essential to the basic operation of the Service, such as maintaining your sign-in session, CSRF defence, and keeping cart or form state. Used without consent.
- Functional: Used for user convenience features such as remembering language and region settings, UI theme, and favourites.
- Performance / Analytics: Collect usage frequency, page navigation paths, and error rates per feature for service improvement. We use the product-analytics tool PostHog; see the Cookies Policy for details.
- Marketing: Used for interest-based ad display, campaign measurement, and retargeting. Only activated where separate consent is given.
For the detailed list of cookies (name, provider, purpose, retention) and how to change settings, see the Cookies Policy. You can refuse or withdraw optional cookies at any time through the in-app cookie settings screen or your browser settings.
In addition to cookies, we may use similar technologies in a limited way, such as local storage, session storage, mobile device identifiers, and pixel tags. These technologies are classified and managed under the same principles as cookies, and non-essential uses are only activated with your consent. For analytics or advertising scripts provided by third parties, we review the scope of data transfer and the provider's privacy policy in advance.
11. Security Measures
We use a combined set of administrative, technical, and physical measures to keep your personal data safe. The main security measures are:
- Transport and at-rest encryption: All web and API communication is encrypted with TLS 1.2 or higher. Key sensitive fields (phone number, payment information, ID document, and similar) are encrypted at storage (at-rest encryption). Encryption keys are managed in a dedicated KMS (Key Management System).
- Access control (RBAC): Staff access to personal data is strictly separated using Role-Based Access Control. We apply the least-privilege principle and require a separate approval step for sensitive actions.
- Audit logs: Access, modification, and deletion of personal data are recorded in internal audit logs and retained for a set period for after-the-fact checks. Unusual access patterns are detected automatically.
- Breach detection and response: We continuously monitor for attempted personal data breaches using firewalls, intrusion detection and prevention systems, log analysis, and unusual-access monitoring. When a breach occurs or is suspected, we will notify the PDPC and affected users within the period set by PDPA §37.
- Regular security audits: We regularly conduct internal checks and external expert security vulnerability reviews, including penetration tests where needed.
- Staff security training: All staff complete personal data protection training at onboarding and periodically, and are familiar with confidentiality obligations and incident response procedures.
- Processor management: Where we outsource personal data processing to an external vendor, we contractually impose the equivalent level of security duties and check compliance regularly.
- Data separation and backup: Production environments are separated from development and test environments both physically and logically. If actual personal data has to be used in development, we first pseudonymise or mask it. Regular backups are kept in encrypted storage, and a disaster recovery procedure is in place so that personal data is not lost in the event of a system failure.
- Vulnerability reporting: We operate a contact channel (contact@gearbid.io) through which external researchers and users can safely report security vulnerabilities. Reported issues are verified quickly and the necessary actions are taken.
We update our security measures continuously in line with advances in technology and changes in the threat environment. No measure can guarantee absolute security, and the Company's duty is to take reasonable protective measures. You should also follow personal-level security practices — password management, device security, avoiding suspicious links, and similar. We provide periodic security guidance to support this.
12. Children's Personal Data
We take the protection of minors' personal data particularly seriously. Under Thai Civil Code the age of majority is 20. We do not collect personal data from users under 20 without the explicit consent of a legal representative (parent or guardian). Even after legal representative consent has been obtained, the scope of collection and use is limited to the minimum needed for service delivery.
Given the B2B nature of a construction equipment rental platform, this Service prohibits use by children under 10. If we find that a child under 10's personal data has been collected without consent, we will destroy it immediately and notify the legal representative.
A legal representative may at any time ask for access, correction, deletion, or suspension of processing of their child's personal data. We verify that the requester is a lawful legal representative and handle the request without delay.
We run additional training and internal checks for children's personal data protection, and we update this Policy if related laws or PDPC guidance change. For Supplier businesses, while adults are generally assumed, we strengthen age verification for individual Suppliers to prevent minors from signing up as businesses.
13. Policy Changes
We may amend this Policy following changes in law, service changes, or policy review. For changes that materially affect your rights or obligations, we will notify you at least 30 days before the effective date of the change through the following means:
- In-app notification and notice-board banner
- Direct notice to the email address you provided at sign-up
- Notice by email or SMS
Where the changes require additional consent, we will ask you to re-consent. For users who do not re-consent, the previous standard may be kept or the relevant feature may be restricted. Minor changes (typo fixes, wording cleanup, and similar) may be reflected without prior notice. Change history is recorded in the version information and lastUpdated field at the bottom of this Policy.
If you want to review a previous version of this Policy, you can contact the DPO. We will provide a previous version within reasonable limits.
To make change notices more effective, we also provide a short, easy-to-read summary of the key changes. This helps you recognise the main changes and take action without having to read the full text. The summary does not replace the legal effect of the main text; the final standard is the body of this Policy.
14. Filing a Complaint with the PDPC
The PDPC (Personal Data Protection Committee) is the Thai government body responsible for enforcing and supervising personal data protection law. If you have a question or objection about the Company's personal data handling, you should first try to resolve it with the Company's DPO. If you are not satisfied with the Company's response, you can file a complaint directly with the PDPC.
The PDPC filing procedure is as follows:
- Prepare the complaint: Prepare the objection and supporting documents using the PDPC's official form.
- Filing channel: You can file your complaint through the PDPC's official website, by post, or at a designated reception desk.
- Review and actions: The PDPC can investigate, hold hearings, issue improvement recommendations, and impose administrative fines on the filed complaint.
The Company has a duty to cooperate with the PDPC's investigation, data requests, and improvement recommendations in good faith, and will promptly implement any required corrective actions in line with the PDPC's decision. Filing a complaint itself does not trigger any adverse treatment in your use of the Service, and the Company will not take any retaliation against a user who files a complaint.
Before filing with the PDPC, it is generally recommended to first try to resolve the issue through direct dialogue with the Company. The Company has a duty to respond to your objection in good faith and promptly, and the DPO oversees this internal complaint-handling process. That said, you have the right to file a complaint with the PDPC directly without going through the internal process, and the Company does not force use of the internal process.
Final interpretation of this Policy and the jurisdiction over personal data processing disputes follow Kingdom of Thailand and Courts of Bangkok, Thailand. For further questions, please contact DPO Eun Sung Jeong (James) (contact@gearbid.io, +66-(0)81-378-0115). The Company's address is No. 68 Bangna-Trad 23, Bangna Nuea, Bangna, Bangkok 10260, and written inquiries are welcome as well.