360nook360nook.com

360Nook — Privacy Policy

Last updated: 11 September 2026

1. Who this covers, and the two roles

360Nook is operated by 360Nook, a business established in Thailand. Contact: [email protected]

We identify the operator by its trading name and a working contact address rather than by an individual's name or street address. That is what a data subject actually needs in order to reach us, and it is what Thailand's PDPA and the GDPR require of a controller — neither asks for a named person to be published.

Two quite different relationships run through this platform, and the difference decides who is answerable for what:

If you are one of our customers' contacts and want your data corrected or removed, ask the business you dealt with. They control it. If you cannot reach them, write to us and we will pass your request on.

2. What we collect about you, our customer

3. What you put into your workspace

This is your data, not ours. It includes:

We do not sell any of it, and we do not use your contacts or their messages to train AI models.

4. Visitors to pages you publish

When someone visits a site, funnel or booking page you publish through 360Nook, we record what is needed to make those pages work and to report on them: page views, which variant of a split test they were shown, and the referral that brought them.

Three cookies do this, and no others are set for tracking:

CookieWhat it does
nook_vidAn anonymous visitor id, so an affiliate referral can be credited
nook_seenRemembers which split-test variant a visitor was shown, so the page does not change under them
nook_v_optinRemembers that a visitor has already submitted a form, so they are not asked twice

We do not use advertising cookies, and we do not share visitor data with ad networks.

Signing in sets a session cookie (authjs.session-token) and a cookie recording which workspace you are viewing (nook_workspace). These are necessary for the platform to work and are not used for tracking.

5. Artificial intelligence, and what leaves our servers

This is the section most worth reading closely, because it is the one where your content goes somewhere else.

When you use an AI feature — a conversation agent, content generation, a knowledge-base answer — the relevant content is sent to a third-party AI provider to be processed. Depending on the model chosen, that provider is Anthropic, OpenAI, or Google. What is sent is whatever that feature needs: for a conversation agent, the messages in that conversation; for content generation, your prompt and the surrounding material.

Two arrangements are possible and the difference matters:

In both cases the content is transmitted to and processed by that provider, outside Thailand, and is subject to their terms and their retention. If that is unacceptable for particular data, do not put that data through an AI feature.

6. Other companies we rely on

PurposeProviderWhat reaches them
Email deliveryBrevo (SMTP)The address, subject and content of each email sent
SMS, voice and phone numbersTwilioNumbers, message content, call metadata
AI processingAnthropic, OpenAI, GoogleSee section 5
Payments you takeYour chosen gateway — Stripe, PayPal, Omise, Xendit, PayMongo, Midtrans, VNPay, Billplz, Komoju, Tap, PayTabs, Mollie, Mercado Pago or RazorpayPayment details, handled by them directly
HostingOur own server infrastructureEverything above, at rest

Where you connect an integration yourself — a social account, a CRM, a calendar — data flows to that service on your instruction and under its own policy.

7. International transfers

Our servers are in Thailand. The providers in sections 5 and 6 operate outside Thailand, in the United States and elsewhere, so using those features transfers data internationally.

If you are in the EU or UK, or your contacts are, this is an area a lawyer should review before you rely on it. We have not yet put standard contractual clauses in place, and we would rather say so than imply otherwise.

8. How long we keep things

9. Security

Passwords are stored only as hashes. Provider credentials and API keys are encrypted at rest. Every workspace's data is isolated at the database level, so one customer's queries cannot reach another's rows. Access is over HTTPS.

No system is perfectly secure. If you believe your account has been compromised, write to [email protected] immediately.

10. Your rights

You may ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to [email protected]. We will respond within 30 days.

If you are a contact of one of our customers rather than a customer yourself, see section 1 — ask the business you dealt with first.

You can stop marketing from a business using 360Nook by using the unsubscribe link in any email, or replying STOP to an SMS. That is honoured automatically and immediately across every channel.

11. Children

The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18.

11a. Connected accounts, and what we do with Google user data

Some features only work if you connect an account you already have elsewhere — a calendar, a mailbox, a social page, a payment provider. Connecting one is always your choice, it is never required to use 360Nook, and you can disconnect it at any time from the screen you connected it on.

When you disconnect, we delete the stored credentials. Anything already created in that account — a booking written into your calendar, a message already sent — stays where it is. Those are records of things that really happened, often with a customer involved, and deleting them because you unlinked an integration would destroy data you never asked us to touch.

Google user data

360Nook's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

If you connect a Google account, this is the whole of it:

Permission we ask forWhyWhat we do with it
calendar.calendarlist.readonly — the names of your calendarsSo you can choose which one to write bookings into, and which to check for clashesShown to you in the Connections screen. We store only the ids you pick.
calendar.freebusybusy intervalsSo we never offer a time when you are already bookedRead at the moment a slot is offered. Returns start and end times only.
calendar.events — create and update eventsSo a booking appears in your calendar the moment it is madeWe write only appointments made through 360Nook, and keep that event's id so we can move or remove that same event later.

We deliberately do not ask for calendar.readonly or full calendar access. Those would let us read the contents of every event you have, and we have no reason to. The narrow permissions above are what the product actually uses.

And, plainly, the things we do not do:

Access tokens are stored encrypted (AES-256-GCM) and are never written to logs or shown on screen. Revoking access from your Google Account permissions page stops everything immediately, with no action needed here.

12. Changes

If this policy changes materially we will say so in the platform before the change takes effect. Previous versions remain available, so it is always possible to establish what this policy said on a given date.

13. Contact

[email protected]