Graffity Maps Privacy Policy

Version 2.0  |  Last updated: 5 September 2026  |  Effective: 5 September 2026

Graffity Maps turns your phone camera into an indoor guide. It works using our Visual Positioning System (VPS), which figures out where you are from what your camera sees, so the app needs access to your camera and to your location. The app is free, and it is funded by sponsored places — businesses inside a venue paying to be promoted in search results and on the map, in much the same way Google Maps promotes businesses. This policy explains exactly what we do with your data, what we never do with it, and the rights and choices you have.

This policy is written to meet Thailand's Personal Data Protection Act B.E. 2562 (2019) (Thai PDPA), Japan's Act on the Protection of Personal Information (APPI), Singapore's Personal Data Protection Act 2012, Malaysia's Personal Data Protection Act 2010 as amended in 2024, and comparable laws in the other markets where Graffity Maps is available. Where a local law gives you stronger rights than this policy describes, that local law applies.

Where Graffity Maps is offered. Graffity Maps is offered in Southeast Asia and Japan. It is not offered or marketed to users in the European Economic Area or the United Kingdom, and we do not monitor the behaviour of people located there. If we begin offering the app in those regions, we will update this policy and put the additional protections required by the GDPR in place before we do.

The short version

  • Camera images are used to locate you, not to identify anyone. We do not run facial recognition, we do not try to work out who is in frame, and we do not build profiles of people who appear in your camera view.
  • Camera frames are not a photo album. Frames used for positioning are processed and then discarded. Before we store any imagery to improve venue maps, every person in it — face and body — is automatically and irreversibly anonymised.
  • Camera imagery is never used for advertising. Neither is your accessibility setting.
  • Ads are sponsored places, and they are always labelled. A shop, gate or restaurant can pay to be promoted in search results or shown as a promoted pin on the map. Sponsored results never change your route, your walking directions or your positioning accuracy.
  • You can turn off ad personalisation. Sponsored places can be chosen using how you use Graffity Maps — what you search for and where you navigate. That is on by default and you can switch it off at any time in Settings → Privacy. Either way you still see sponsored places, just chosen from where you are rather than from your history.
  • We do not track you across other apps or websites, and there is no third-party ad network inside the app. Graffity sells and serves the sponsored places itself, so your advertising data never leaves us.
  • We do not sell your personal data and we do not share it with data brokers.
  • Positioning runs while you are navigating, not in the background. We do not track your location when the app is closed.
  • Venue operators do not get your movements. They receive aggregated, de-identified statistics about how their venue is used, never an individual trail.
  • You stay in control. Two switches in Settings → Privacy govern map improvement and ad personalisation, you can withdraw camera or location permission at any time in your device settings, and you can ask us to delete your data by emailing privacy@graffity.tech.

This summary is for orientation only. The full sections below are the binding version.

1. Who we are and how to contact us

The controller of your personal data (the “Data Controller” under the Thai PDPA and the Malaysia PDPA, the “organisation” under the Singapore PDPA, and the “personal information handling business operator” under the APPI) is:

  • Graffity Technologies Co., Ltd. (“Graffity”, “we”, “us”, “our”)
  • 1 Empire Tower, South Sathorn Road, Yannawa, Sathorn, Bangkok, Thailand
  • General privacy enquiries and rights requests: privacy@graffity.tech
  • Data Protection Officer (Thai PDPA s.41): privacy@graffity.tech
  • App support: contact@graffity.tech

We have appointed a Data Protection Officer as required by Thai PDPA s.41 and the Malaysia PDPA, who is also our designated contact for complaints and requests under the APPI and the Singapore PDPA, reachable at the address above.

2. What this policy covers

This policy applies to the Graffity Maps mobile application and the Graffity services that support it, including the Visual Positioning System that computes your position from camera imagery, our routing and search services, the advertising shown in the app, and the account and support systems behind them (together, the “Service”).

This policy does not cover:

  • Our other products, which have their own policies — including Graffity Scanners and Graffity Viewer.
  • The venues you visit. A mall, station, airport or hospital operates its own Wi-Fi, CCTV, loyalty programmes and apps under its own privacy notices. Using Graffity Maps inside a venue does not put us in control of that venue's own data collection.
  • Advertisers and the websites or apps an ad takes you to, which are controlled by whoever operates them.
  • Apple, Google or other platform operators, who process data about your app downloads, purchases and device under their own policies.
  • Third-party sites or services you reach through links in the app.

3. Definitions

  • Account: an optional Graffity Maps account. Most navigation features work without one.
  • Camera frame: a single still image captured from your device camera and used by the Visual Positioning System.
  • Contextual ad: a sponsored place chosen from what is on your screen right now — the venue you are in, the floor you are on, or the search you just typed — and not from any history or profile.
  • Device: the phone or tablet on which you use the Service.
  • Personal data: any information relating to an identified or identifiable person. In this policy it has the meaning given by the applicable law, including “personal data” under the Thai PDPA, the Malaysia PDPA and the Singapore PDPA, and “personal information” and “retained personal data” under the APPI.
  • Personalised ad: a sponsored place chosen using a record of how you have used Graffity Maps — your past searches, destinations and the venues you have navigated in.
  • Processing: anything done with personal data, including collecting, storing, using, sharing, and deleting it.
  • Sensitive data: sensitive personal data under Thai PDPA s.26, special care-required personal information (yohairyo kojin joho) under the APPI, and comparable categories under the other laws that apply — for example data revealing health or disability, religion, or biometric data used to identify a person.
  • VPS (Visual Positioning System): Graffity's technology that determines your position and heading by comparing features extracted from camera frames against a prebuilt 3D map of a venue.
  • Sponsored place: a shop, restaurant, counter or other destination whose operator pays to have it promoted in Graffity Maps. Always labelled as sponsored.
  • Venue operator: the owner or operator of a mapped building, such as a mall, transit or airport operator.
  • You: the individual using the Service.

4. What we collect, why, and on what legal basis

We collect only what the Service needs. The table below lists every category of personal data we process, why we process it, and our legal basis under the Thai PDPA. The Singapore and Malaysia PDPAs are consent-based with comparable exceptions for processing necessary to provide a service you asked for and for an organisation's legitimate interests; we rely on the equivalent basis in each market. Under the APPI, the “why we process it” column is our specified purpose of use, and we will not use your personal information beyond it without your consent. Where a basis is consent, you can withdraw it at any time (see section 8) without affecting processing that already took place.

Data Why we process it Legal basis (Thai PDPA)
Camera frames and derived visual features — images from your rear camera while AR navigation is on, and the mathematical feature descriptors extracted from them To compute where you are and which way you are facing, so we can draw AR directions onto the floor in front of you s.19 consent
Indoor position, heading and floor level To place you on the venue map, route you, and switch floors correctly s.24(3) contractual necessity
Coarse device location and GPS — used at the edges of a venue and to work out which venue you are in To select the right venue map and to hand over between outdoor and indoor positioning s.19 consent
Navigation activity — search terms, chosen destination, route requested, route followed, arrival, and whether you asked for a step-free route To deliver directions, to correct wrong or stale map data, and to see which routes fail so we can fix them s.24(3) contractual necessity; s.24(5) legitimate interest
Accessibility preference — if you turn on step-free routing (see section 6) To route you away from stairs and escalators. Never used for advertising s.26 explicit consent
Saved places — your parking spot and any place you bookmark To let you walk back to your car or a saved spot s.24(3) contractual necessity
Account data — email address, display name, sign-in identifier, and the identifier supplied by Apple, Google or another sign-in provider if you use one To create and secure your account and sync saved places across your devices. Optional — navigation works without an account s.24(3) contractual necessity
Device and technical data — device model, operating system version, app version, language and region, camera and sensor capabilities, coarse network information, and a resettable app instance identifier To make VPS and AR rendering work correctly on your hardware, to keep the Service secure, and to prevent abuse s.24(5) legitimate interest
Diagnostics — crash reports, error logs, positioning failure events, tracking-quality metrics, latency and frame rate To find and fix crashes and positioning failures s.24(5) legitimate interest
Map improvement data — scanning data (camera frames and visual features, with every person anonymised before storage) and navigation data, retained beyond the positioning request. Governed by the Help improve maps switch To keep venue maps current, fix drift and gaps, and improve VPS accuracy s.24(5) legitimate interest, with an unconditional opt-out
Advertising data — in-app interaction and navigation history used to select ads, plus ad delivery events such as impressions, clicks and frequency. Governed by the Personalised ads switch (see section 11) To choose which sponsored places to promote to you based on how you use Graffity Maps, and to measure and cap how often you see them s.24(5) legitimate interest, with an unconditional opt-out; s.19 consent in markets whose law requires opt-in for this purpose
Contextual ad data — the venue and floor you are currently in, the search you just typed, the screen you are on, coarse region and language, and non-identifying delivery data To promote sponsored places relevant to where you are and what you just searched for, and to fund the free app when you have not enabled personalised ads s.24(5) legitimate interest
Product analytics — which screens and features you use, in aggregate To understand which features are worth keeping and where people get stuck s.24(5) legitimate interest
Support communications — your messages, contact details and any information you choose to send us To answer you and keep a record of the issue s.24(3) contractual necessity; s.24(5) legitimate interest
Records required by law — consent records, rights request records, and records of legally required disclosures To demonstrate compliance and to respond to lawful requests s.24(6) legal obligation

Where we rely on legitimate interests

Where the table cites legitimate interests, we have weighed our interest against your privacy and concluded that the processing is limited to what is needed, uses the least identifying data that will work, and would be expected by a reasonable user of a free, ad-supported navigation app. You can object to any of it (see section 15), and for map improvement and personalised ads you can object simply by moving the switch in Settings → Privacy. You can ask us for a summary of the balancing assessment by emailing privacy@graffity.tech.

What happens if you decline

You are never required to give us data, but some data is unavoidable for the Service to function:

  • Camera access: without it, VPS positioning and AR directions cannot work. The 2D map view and search remain available.
  • Location access: without it, we cannot reliably tell which venue you are in, so you will need to select the venue manually.
  • Account: optional. Declining means saved places stay on that one device.
  • Help improve maps: optional. Turning it off has no effect on any navigation feature. Maps in venues you visit may be corrected more slowly.
  • Personalised ads: optional. Turning it off does not remove sponsored places and does not reduce any feature — the app is free either way. Sponsored places will be chosen from where you are and what you just searched, rather than from your history.

5. How camera and Visual Positioning data is handled

This is the part of Graffity Maps with the most privacy at stake, so we set it out in detail.

What the camera is doing

While AR navigation is active, the app captures frames from your rear camera and extracts visual features — abstract numerical descriptors of corners, edges and textures in the scene. Those features are matched against a prebuilt 3D map of the venue to compute your position and heading. The app is looking at the geometry of the building, not at the people in it.

Where the processing happens

Depending on your device and the venue, feature extraction and matching happen on your device, on our servers, or split between the two. Where a request is sent to our servers, it contains the camera frame or the features extracted from it, the venue identifier, device sensor readings, and a request identifier — and nothing that identifies you by name.

Anonymisation of people in imagery

Before any camera imagery is written to storage, an automated process detects every person in the frame and irreversibly anonymises them — the whole body, not only the face. The anonymisation is applied to the stored image itself and cannot be undone or reversed by us or by anyone else. We do not keep an unmasked original.

The same process removes other details in the frame that could point to a particular person — including vehicle licence plates in car parks, and identifying text such as name badges, documents and screens caught in view. What is left is the building: floors, walls, signage, fixtures and shopfronts.

How long frames are kept

  • Positioning requests: frames and features sent for positioning are held only for as long as the request needs and are then deleted, and in no case held longer than 24 hours. That short buffer exists only so that failed positioning attempts can be diagnosed.
  • Map improvement: while the Help improve maps switch is on, anonymised imagery may be retained for up to 24 months to update and correct venue maps. Turning the switch off stops further retention and, on request, deletes what we hold.
  • Never: we do not retain camera frames for advertising, for identifying individuals, or for sale or licensing to third parties.

Other people in frame

Pointing a phone down a corridor inevitably catches other people. We have designed the Service to minimise the consequences: features used for positioning are geometric and are not a face template; we do not perform facial recognition or any other biometric identification; and every person in stored imagery is fully anonymised as described above. We do not use camera frames to build biometric identifiers, so we do not process biometric data within the meaning of Thai PDPA s.26 or the APPI. If you believe you appear in imagery we hold, you can still exercise the rights in section 15.

Camera imagery is never used for advertising

Nothing seen by the camera — the shops you pass, the products on shelves, the people around you — is used to select, target or measure sponsored places, and no camera imagery or visual feature data is shared with any advertiser. Ad selection uses only the data described in section 11.

Your camera roll

Graffity Maps does not read your photo library. Camera access is used for the live camera stream only. If a future feature needs photo library access, we will ask for it separately and update this policy first.

Recording

The app does not record video or audio. The microphone is not used.

6. Accessibility preferences and sensitive data

Graffity Maps offers step-free routing for wheelchair users, people with strollers and people with luggage. We recognise that turning this setting on may reveal something about your health or disability. That makes it sensitive personal data under Thai PDPA s.26 and special care-required personal information under the APPI, which we may only collect with your prior explicit consent. We therefore:

  • keep the preference on your device by default, and only sync it to your account if you have an account and give explicit consent;
  • use it solely to calculate routes — never for advertising, ad targeting, segmentation or marketing of any kind, whether or not you have enabled personalised ads;
  • exclude it from the aggregated statistics we provide to venue operators, except as a count of step-free route requests per venue that cannot be linked to any individual;
  • let you turn it off and delete it at any time in app settings, which erases it from your account within 30 days.

We do not ask for, and ask you not to send us, any other sensitive data — including health records, religious or political views, or trade union membership.

7. What we never do

Graffity Maps carries advertising, so it is worth being precise about the limits we hold ourselves to:

  • We do not sell your personal data, and we do not share it with data brokers.
  • We do not embed third-party advertising, measurement or mediation SDKs in the app. We run advertising on our own systems.
  • We do not track you across other apps or websites. Everything we use to select ads comes from your activity inside Graffity Maps.
  • We do not use camera imagery or visual feature data to select, target or measure sponsored places.
  • We do not let an advertiser see your indoor position trail, your identity or your contact details.
  • We do not let paid promotion change your route. Sponsored places never alter walking directions, distances or positioning accuracy, and are always labelled.
  • We do not use your accessibility setting, or any other sensitive data, for advertising.
  • We do not run facial recognition or any other biometric identification on camera imagery.
  • We do not store camera imagery in which people have not been anonymised.
  • We do not track your location in the background, when the app is closed, or outside the venues you are navigating.
  • We do not give venue operators, landlords, retailers or advertisers the ability to identify or follow an individual shopper.
  • We do not use your data to make automated decisions with legal or similarly significant effects on you.

8. Your privacy choices and device permissions

The two switches

Two settings in Settings → Privacy inside Graffity Maps control the optional uses of your data. Each can be changed at any time, and a change takes effect immediately for future processing:

  • Help improve maps — lets us use your scanning and navigation data to keep venue maps accurate. Turning it off stops that use; navigation is unaffected.
  • Personalised ads — lets us use your in-app interaction and navigation data to choose which sponsored places to promote to you. Turning it off means sponsored places are chosen contextually instead, from the venue you are in and the search you just typed. It starts on, and you can switch it off at any time. In any market whose law requires opt-in consent for this purpose, it starts off and we ask you first.

Withdrawing consent, or switching off a setting we run on legitimate interests, does not affect the lawfulness of processing that already happened. You can also ask us to delete the data already collected under either setting — see section 15.

Device permissions

The app asks for the minimum permissions it needs, at the moment it needs them:

  • Camera — required for AR navigation and VPS positioning.
  • Location (while using the app) — to identify your venue and hand over between outdoor and indoor positioning. We do not request “always” or background location.
  • Motion and orientation sensors — to keep AR arrows stable as you move.
  • Notifications — optional, for arrival and service messages.
  • Bluetooth — not required. Graffity Maps needs no beacons or added hardware in the building.
  • App tracking (iOS) — not requested. We do not track you across other companies' apps or websites, so we do not ask for App Tracking Transparency permission.

You can grant or revoke any of these at any time in Settings → Privacy on iOS or Settings → Apps → Permissions on Android. Revoking camera or location permission withdraws the consent we rely on for the corresponding processing; the AR features will stop working, but the rest of the app continues.

9. Who we share data with

We share personal data only with the categories of recipient below, and only as much as each one needs.

  • Cloud infrastructure and hosting providers that run our VPS, routing, ad serving and account services, acting as our processors under written contracts.
  • Crash reporting and analytics providers, acting as our processors, limited to diagnostics and product analytics.
  • Customer support and email providers that handle your messages to us.
  • Venue operators — aggregated, de-identified statistics only. See section 10.
  • Advertisers and the businesses whose places are promoted — aggregated campaign reporting only, never your identity or your movements. See section 11.
  • Professional advisers and auditors, where needed and under a duty of confidence.
  • Authorities, courts and law enforcement, where we are legally required to disclose, or where disclosure is necessary to protect the rights, safety or property of Graffity, our users or the public. We assess each request, disclose the minimum necessary, and tell affected users where we are permitted to.
  • An acquirer, if Graffity is involved in a merger, acquisition, financing or sale of assets. We will notify you before your personal data becomes subject to a different privacy policy, and your rights under this policy carry over until then.

All processors act on our documented instructions, are bound by confidentiality, are required to apply appropriate security measures, and may not use your data for their own purposes. A current list of our processors, including their locations, is available on request from privacy@graffity.tech.

10. Venue operators and analytics

Venue operators pay to have their buildings mapped, and they want to know how the building is working. What they receive from us is aggregated and de-identified: for example the number of navigation sessions per day, the most searched destinations, common origin-destination pairs, average walking times, floors where positioning tends to fail, and counts of step-free route requests.

We apply minimum aggregation thresholds so that small counts cannot be traced back to one person, and we do not provide operators with individual trails, device identifiers, camera imagery, account identifiers or contact details. Once aggregated in this way, the statistics are no longer personal data.

If a venue asks you to identify yourself — for example through its own loyalty programme, Wi-Fi login or app — that is the venue's own processing under the venue's own privacy notice, and not covered by this policy.

11. Advertising

Graffity Maps is free to use and is funded by advertising. Our ads are sponsored places: a shop, restaurant, service counter or other destination inside a mapped venue can pay to be promoted — appearing higher in search results, or as a promoted pin on the 2D map. This is the model Google Maps uses for promoted businesses.

Rules we hold ourselves to

  • Sponsored content is always labelled as sponsored or promoted, clearly and next to the item itself.
  • Paying does not change your route. Walking directions, distances, floor transitions and positioning accuracy are calculated from the map and your position, never from who has paid. We will not route you past a paying shop or lengthen your walk for commercial reasons.
  • Safety and accessibility come first. Step-free routing, emergency exits, lifts and accessible facilities are never demoted, hidden or reordered because of paid promotion.
  • Organic results stay honest. If you search for a specific place by name, we show you that place.

What we use to choose which sponsored places to show

Depending on your Personalised ads setting, we use one of two sets of signals:

  • Contextual (always): the venue and floor you are currently in, the search term you just typed, the screen you are on, your coarse region and your language. These are about your present moment, not a history of you.
  • Personalised (only when the setting is on): in addition to the above, a record of how you have used Graffity Maps — your past searches, the destinations you chose, the categories you looked at and the venues you have navigated in.

We also record ad delivery events — that a sponsored place was shown, whether it was tapped, and how often you have seen it — so that we can cap repetition and bill advertisers correctly.

What is never used for advertising

  • Camera imagery and visual feature data.
  • Your precise indoor position trail — the step-by-step path you walked.
  • Your accessibility preference, or any other sensitive data.
  • Your saved places, including where you parked.
  • Your email address, name or account identifier, and the contents of your support messages.

Your choice

Personalisation is on by default, and you can turn it off at any time in Settings → Privacy with no loss of functionality. Turning it off is a single switch, takes effect immediately, and does not require you to contact us or give a reason. We rely on our legitimate interest in funding a free app, and your right to object to that is unconditional.

In any market whose law requires opt-in consent for this kind of processing, the switch starts off instead and we ask for your consent first, in a choice as easy to refuse as to accept. If you refuse, you still see contextual sponsored places and no feature is withheld or degraded.

Turning personalisation off stops us using your history to select sponsored places from that moment on. You can also ask us to delete the advertising history we already hold — see section 15.

No cross-app or cross-site tracking

Everything we use for advertising comes from your activity inside Graffity Maps. We do not follow you into other companies' apps or websites, we do not buy or ingest data about you from data brokers or other sources, and we do not use cross-app advertising identifiers such as Apple's IDFA or the Android Advertising ID for tracking. Because we do not track you across other companies' apps and websites, we do not ask for App Tracking Transparency permission on iOS.

What advertisers receive

Advertisers and promoted businesses receive aggregated campaign reporting: how many times their place was shown, how many people tapped it, how many started navigating to it, and broad breakdowns such as day and venue. They do not receive your identity, contact details, device identifiers, position trail, camera imagery or any list of individuals. We do not sell your personal data to them or to anyone else.

We run advertising ourselves

Sponsored places are sold, chosen, served and measured entirely by Graffity, on our own systems. Graffity Maps contains no third-party advertising, measurement or mediation SDK. No advertising network, ad exchange, demand-side platform or data broker receives your data, and none of them runs code inside the app. Your advertising data stays within Graffity and is used only to choose and cap the sponsored places you see.

We do not sell your personal data, and we make none of it available for anyone else to buy.

Why am I seeing this?

Each sponsored place carries an option to see why it was shown to you and to change your advertising settings from that point in the app.

Young people

We do not knowingly use personalised advertising for anyone below the age at which they can consent on their own under their local law (see section 17). Where we know or reasonably believe a user is below that age, only contextual sponsored places are shown.

12. Where your data is stored and international transfers

Where your data is stored

  • If you use Graffity Maps in Japan, your personal data is stored and processed on cloud infrastructure located in Japan. It is not stored outside Japan.
  • If you use Graffity Maps elsewhere in East or Southeast Asia, your personal data is stored and processed on cloud infrastructure located in Singapore.

In neither case is your personal data stored in Thailand, even though Graffity Technologies Co., Ltd. is established there.

[[CONFIRM — this one materially changes the section below. Can Graffity staff or systems outside the storage country reach this data: (a) can staff in Thailand access personal data held in the Japan or Singapore region, through an admin console, support tool or production database; and (b) does anything holding personal data move between the Japan and Singapore regions, such as shared analytics, backups or model training? If either is yes for Japan, APPI Article 28 applies after all and the receiving country must be named here.]]

Japan

Because personal data collected in Japan stays in Japan, we do not make a cross-border transfer of it, and APPI Article 28 does not apply. Entrusting the storage of personal data to a service provider within Japan is not a provision of personal data to a third party under APPI Article 27(5)(i), so we do not need your consent for it. Our provider acts on our instructions only, may not use your data for its own purposes, and is bound by written data protection terms. If this ever changes — if we need to store or access Japanese users' personal data outside Japan — we will update this policy and put an Article 28 basis in place before we do.

Other markets

If you are outside Singapore, storing your data in Singapore is a cross-border transfer, and we apply these safeguards:

  • Thailand. Transfers of personal data out of Thailand comply with Thai PDPA ss.28–29 — to recipients in countries with adequate protection, under appropriate safeguards, or with your consent after we have informed you of the standards at the destination.
  • Singapore. Personal data held in Singapore is protected by the Singapore PDPA. Where we transfer it onward, we comply with the Transfer Limitation Obligation, under contracts requiring a comparable standard of protection.
  • Malaysia. Transfers out of Malaysia comply with the cross-border transfer requirements of the Malaysia PDPA as amended in 2024.

Our cloud providers act as our processors in both regions. They store and serve the data on our instructions, may not use it for their own purposes, and are bound by written data protection terms. We will name the provider for your region, and give you details of the safeguards that apply to a specific transfer, on request to privacy@graffity.tech.

13. How long we keep data

We keep personal data only as long as we need it for the purpose we collected it for, then delete or irreversibly anonymise it. Our standard periods are:

Data Retention Why
Camera frames and features sent for positioning Deleted after the request, and in any case within 24 hours Only needed to answer the positioning request and diagnose failures
Map improvement imagery (anonymised; Help improve maps on) Up to 24 months, or until you switch the setting off Venue layouts change; maps need periodic revision
Position and route history linked to your account 13 months, then aggregated or deleted Enough to diagnose recurring routing problems across a full year of venue changes
Search terms and navigation events not linked to an account 13 months Service quality analysis
Advertising history used for personalisation 13 months, or until you switch Personalised ads off or ask us to delete it Keeps promotion relevant without holding a long-term profile
Ad delivery and billing records (impressions, taps, frequency) Aggregated within 90 days; aggregated billing records kept as required for tax and accounting Billing advertisers accurately and capping repetition
Accessibility preference Until you change it or delete your account; deleted within 30 days of either It is a live setting, not a history
Saved places, including your parking spot Stored on your device until you delete it; parking spots auto-expire after 7 days. If synced to an account, deleted within 30 days of deletion or account closure You control your own saved places
Account data For the life of the account, then deleted within 30 days of closure Needed to operate the account
Crash reports and diagnostic logs 90 days Long enough to reproduce and fix a defect
Security and access logs 12 months Incident investigation and abuse prevention
Product analytics 25 months, then aggregated Year-on-year comparison
Support correspondence 24 months after the case closes Handling repeat and related issues
Consent, setting-change and rights-request records As long as required by applicable law, and at least 3 years Demonstrating compliance
Records needed for legal claims, tax or accounting As required by the applicable limitation or statutory period, up to 10 years in Thailand Legal obligation and defence of claims

Aggregated and irreversibly anonymised statistics — which cannot be linked back to you — may be kept indefinitely. Backups are overwritten on a rolling cycle, so deleted data may persist in encrypted backups for a short period after deletion from live systems before being purged.

14. How we protect data

We apply technical and organisational measures appropriate to the risk, including:

  • encryption in transit (TLS) and encryption at rest for stored personal data;
  • role-based access control, least-privilege access and multi-factor authentication for staff systems;
  • separation of camera imagery from account identifiers, so positioning requests are not stored alongside who you are;
  • automated, irreversible anonymisation of every person appearing in imagery before it is stored;
  • separation of advertising data from camera imagery, position trails and sensitive settings, enforced in our systems and not only by policy;
  • logging and monitoring of access to personal data;
  • written data processing agreements and security review of our providers;
  • internal policies, staff confidentiality obligations and privacy training;
  • a documented incident response process.

If a personal data breach occurs, we will report it to the regulators that require it and tell affected users where the law requires or the risk warrants it. In particular we will notify:

  • Thailand's Office of the Personal Data Protection Committee within 72 hours of becoming aware, and affected users without delay where the breach is likely to result in a high risk to their rights and freedoms (Thai PDPA s.37(4));
  • Japan's Personal Information Protection Commission, with a preliminary report promptly and a full report within the period the PPC prescribes, and affected individuals promptly, for breaches involving special care-required information, a risk of financial loss, improper purpose, or large numbers of people;
  • Singapore's Personal Data Protection Commission within 3 calendar days of assessing a breach to be notifiable, and affected individuals as soon as practicable;
  • Malaysia's Personal Data Protection Commissioner as soon as practicable and in any case within 72 hours, and affected data subjects within the period the law prescribes.

No system is perfectly secure. Please keep your device locked and your account credentials private, and tell us at privacy@graffity.tech if you believe your account has been compromised. Security researchers can report vulnerabilities to the same address.

15. Your rights and how to exercise them

Subject to the conditions and exemptions in the law that applies to you, you have the right to:

  • Be informed about how we use your data — this policy.
  • Access the personal data we hold about you, and receive a copy.
  • Rectify data that is inaccurate, out of date or incomplete.
  • Erase your data (“right to be forgotten”) where we no longer need it, where you withdraw consent, or where you successfully object. This includes asking us to delete the advertising history and map improvement data we hold about you.
  • Restrict our processing while a dispute about accuracy or lawfulness is resolved.
  • Object to processing based on legitimate interests, and to require us to stop using your data for direct marketing at any time — a right given by Thai PDPA s.32, Malaysia PDPA s.43 and the APPI's right to request cessation of use. You can exercise it by switching Personalised ads off, or by emailing us.
  • Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
  • Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
  • Request that we stop using or disclosing your data, where the law that applies to you provides that right, including under APPI Articles 35 and following.
  • Not be subject to decisions based solely on automated processing that have legal or similarly significant effects — we do not make any (see section 18).
  • Complain to your data protection authority (see section 20).

How to make a request

Email privacy@graffity.tech with the request you want to make. Some requests can be completed in the app: you can change both privacy switches in Settings → Privacy, edit or delete saved places and your accessibility preference in app settings, and delete your account from Settings → Account → Delete account.

We will:

  • acknowledge your request promptly and verify your identity, asking only for what we need to be sure it is you — usually confirmation from the email address on your account;
  • respond within 30 days where the Thai PDPA applies;
  • respond within 30 days where the Singapore PDPA applies, or tell you when we will respond if we cannot meet that;
  • respond within 21 days where the Malaysia PDPA applies;
  • respond without delay where the APPI applies, and tell you the reason if we cannot grant a request in full;
  • charge nothing, unless a request is manifestly unfounded or excessive, in which case we will explain the fee or the refusal and your right to complain before doing anything.

If you do not use an account, we may hold no data that can be linked to you. In that case we will say so, and explain what you could provide to let us locate your records — but we will not collect extra data about you solely to search for you.

Requests may be made by an authorised representative, on evidence of their authority.

16. Region-specific information

Thailand

We process personal data as a Data Controller under the Thai PDPA. Our Data Protection Officer can be reached at privacy@graffity.tech. You may complain to the Office of the Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society (pdpc.or.th).

Japan

We act as a personal information handling business operator under the APPI. The purposes of use of your personal information are the “why we process it” entries in section 4, and we will not use your personal information beyond them without your consent. We do not provide your personal data to third parties for their own purposes, and we do not operate an opt-out third-party provision scheme. Personal data collected in Japan is stored and processed in Japan, as set out in section 12, so it is not transferred out of the country. You have the rights of disclosure, correction, addition, deletion, cessation of use and cessation of third-party provision in respect of retained personal data, exercisable through privacy@graffity.tech. Complaints may be made to the Personal Information Protection Commission (ppc.go.jp).

Singapore

We comply with the Singapore PDPA, including the Consent, Purpose Limitation, Notification, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation and Accountability obligations. Complaints may be made to the Personal Data Protection Commission (pdpc.gov.sg).

Malaysia

We comply with the Malaysia PDPA and its principles, including the General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access principles. Complaints may be made to the Personal Data Protection Department (JPDP) (pdp.gov.my).

Other markets

Where Graffity Maps is available in Indonesia, the Philippines, Vietnam, Taiwan, South Korea or elsewhere, we process personal data in accordance with the applicable local data protection law, including local rights of access, correction and deletion and local breach notification duties. Contact privacy@graffity.tech for jurisdiction-specific details.

17. Children and young people

Graffity Maps is not directed at children. We do not knowingly collect personal data from:

  • anyone under 20 in Thailand, where Thai PDPA s.20 requires the consent of a parent or person exercising parental power, unless the minor is legally capable of giving consent alone;
  • children under 15 in Japan, where guidance from the Personal Information Protection Commission expects the consent of a guardian;
  • children under 13 in Singapore, or under 18 in Malaysia, without parental consent.

We do not knowingly show personalised advertising to anyone below the applicable age. Where we know or reasonably believe a user is below it, only contextual sponsored places are shown.

If you are below the applicable age, please use Graffity Maps only with a parent or guardian's involvement. If we learn that we hold personal data collected from a child without the required consent, we will delete it promptly. Parents and guardians can contact privacy@graffity.tech to review or delete a child's data.

18. Automated decision-making and profiling

Graffity Maps runs automated processing to do its job — computing your position from camera imagery and calculating routes. Those computations affect the directions you see, and nothing else.

Where personalised ads are enabled, we build a limited profile of your in-app activity and use it to decide which sponsored places to promote to you. You can stop it at any time by switching the setting off. It affects which promotions you see and nothing more. We make no decisions based solely on automated processing that produce legal effects or otherwise significantly affect you.

A safety note, not a privacy one: AR directions are guidance, not a substitute for paying attention. Watch where you are walking, obey venue signage and staff instructions, and do not rely on the app in an emergency. See our AR safety guidance.

19. Changes to this policy

We may update this policy as the Service changes or the law does. When we do, we will update the version number and the “Last updated” date at the top of this page and post the new version here.

If a change materially affects how we use your personal data, we will give you notice before it takes effect — in the app, by email if we have your address, or both. Where a change requires your consent, we will ask for it and will not rely on the change until you give it. We keep previous versions and can send you one on request.

20. Contact us and how to complain

Questions, rights requests and complaints about privacy:

We would like the chance to put things right first, so please come to us before escalating. But you do not have to: you always have the right to complain directly to your data protection authority, and where the law allows, to seek a judicial remedy. The relevant authorities for the main markets are listed in section 16.