Skip to main content
Daofa Plus badge markDaofa Plus

Version 2.0.0 — effective 1 August 2026

Daofa Plus Privacy Policy

This Privacy Policy explains how Daofa Sole Co.,Ltd (enterprise registration No. 01-00028958; Ban Khamsavat, Xaysettha District, Vientiane Capital, Lao PDR), the operator of the Daofa Plus application, collects, uses, shares, and protects your personal data when you use the Daofa Plus app. It is a separate document from the Terms and Conditions.

1. Data we collect

  • Account data. Your mobile phone number is required to register and sign in. Your display name and email address are optional and provided by you.
  • Verification data. When you sign in we send a one-time password (OTP) to your phone by SMS or, if you choose, by WhatsApp. We record when the code was requested, the delivery channel, and the IP address of the request. OTP codes are stored only in protected (hashed) form and expire quickly.
  • Transaction data. Records of your orders (items or services, amounts, order numbers), top-ups, points earned and spent, point transfers, withdrawals, and the related bank reference numbers.
  • Payment data. When you pay through a bank (BCEL One, LDB Trust, LVB, JDB) or receive a refund by bank transfer, we receive and keep transaction confirmations from the bank, including the reference number and a masked form of the paying account. We never receive or store your bank password, PIN, or full card details.
  • Device and technical data. Device model, operating system, app version, language setting, push notification token, and IP address, together with technical logs needed to keep the service secure and working.
  • Referral data. If you use a referral code, we record the link between the referrer and the referred account and the resulting referral rewards.
  • Biometric sign-in. If you enable fingerprint or face sign-in, the biometric check happens entirely on your device using your phone's own secure system. Your fingerprint or face data is never sent to us and we cannot access it.

2. How we use your data

  • To provide the service: register your account, process orders, top-ups and payments, credit points, and process withdrawals to your bank account.
  • To verify your identity through OTP and protect your account.
  • To prevent and detect fraud, duplicate payments, and abuse of the service.
  • To meet our legal duties as a business operator, including record-keeping, accounting, and tax obligations under Lao PDR law.
  • To send service notifications (for example order status, payment status, points earned) and, with your consent, promotional messages. You can turn promotional notifications off in your device settings at any time.
  • To provide customer support and resolve disputes about orders and payments.

3. Who we share data with

We share personal data only as far as needed to run the service, and we never sell your personal data to anyone.

  • Banks (BCEL One, LDB Trust, LVB, JDB) — to process your payments and to transfer refunds to your account.
  • Telecommunication operators (LTC, Unitel and others) — to deliver OTP messages and process phone top-up services.
  • WhatsApp (Meta) — only if you choose WhatsApp as your OTP channel.
  • Service providers — cloud hosting on Amazon Web Services (Singapore region), Google Firebase for push notifications, and Cloudinary for image storage. These providers process data for us under their own security commitments.
  • State authorities of the Lao PDR — where disclosure is required by law, regulation, or a lawful order.

4. Where your data is stored

Our servers are hosted on Amazon Web Services in Singapore. Data is encrypted in transit between your device and our servers.

5. How long we keep data

  • Account and transaction records are kept while your account is active and afterwards for as long as Lao PDR law on accounting, taxation, and anti-money-laundering requires.
  • OTP records are short-lived and removed automatically after they expire.
  • Technical logs are kept only as long as needed for security and troubleshooting.

6. Security

We protect your data with encryption in transit, strict access controls, hashed storage of secrets, and continuous monitoring. Payments are only ever confirmed against a verifiable bank reference. No system is perfectly secure — please keep your phone and SIM safe and never share an OTP code with anyone, including people claiming to be our staff.

7. Your rights

  • Ask for a copy of the personal data we hold about you.
  • Correct your profile data (name, email) in the app at any time.
  • Ask us to delete your account and personal data. We will do so except where the law requires us to keep certain transaction records.
  • Withdraw consent to promotional notifications at any time.

To exercise these rights, contact us using the details below. We will respond within a reasonable time.

8. Age limit

The Daofa Plus service is for persons aged 18 or over. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete the account.

9. Changes to this policy

When we change this policy we will publish the new version in the app with a new version number and effective date. Continued use of the app after the effective date means the new version applies.

10. Contact us

Daofa Sole Co.,Ltd
Ban Khamsavat, Xaysettha District, Vientiane Capital, Lao PDR
Phone: +856 20 9999 9944
Email: support@daofagroup.com

This policy is governed by the laws of the Lao People's Democratic Republic, including the Law on Electronic Data Protection.