Version 2.0 | Last updated: 5 September 2026 | Effective: 5 September 2026
Graffity Maps turns your phone camera into an indoor guide. It works using our Visual Positioning System (VPS), which figures out where you are from what your camera sees, so the app needs access to your camera and to your location. The app is free, and it is funded by sponsored places — businesses inside a venue paying to be promoted in search results and on the map, in much the same way Google Maps promotes businesses. This policy explains exactly what we do with your data, what we never do with it, and the rights and choices you have.
This policy is written to meet Thailand's Personal Data Protection Act B.E. 2562 (2019) (Thai PDPA), Japan's Act on the Protection of Personal Information (APPI), Singapore's Personal Data Protection Act 2012, Malaysia's Personal Data Protection Act 2010 as amended in 2024, and comparable laws in the other markets where Graffity Maps is available. Where a local law gives you stronger rights than this policy describes, that local law applies.
Where Graffity Maps is offered. Graffity Maps is offered in Southeast Asia and Japan. It is not offered or marketed to users in the European Economic Area or the United Kingdom, and we do not monitor the behaviour of people located there. If we begin offering the app in those regions, we will update this policy and put the additional protections required by the GDPR in place before we do.
This summary is for orientation only. The full sections below are the binding version.
The controller of your personal data (the “Data Controller” under the Thai PDPA and the Malaysia PDPA, the “organisation” under the Singapore PDPA, and the “personal information handling business operator” under the APPI) is:
We have appointed a Data Protection Officer as required by Thai PDPA s.41 and the Malaysia PDPA, who is also our designated contact for complaints and requests under the APPI and the Singapore PDPA, reachable at the address above.
This policy applies to the Graffity Maps mobile application and the Graffity services that support it, including the Visual Positioning System that computes your position from camera imagery, our routing and search services, the advertising shown in the app, and the account and support systems behind them (together, the “Service”).
This policy does not cover:
We collect only what the Service needs. The table below lists every category of personal data we process, why we process it, and our legal basis under the Thai PDPA. The Singapore and Malaysia PDPAs are consent-based with comparable exceptions for processing necessary to provide a service you asked for and for an organisation's legitimate interests; we rely on the equivalent basis in each market. Under the APPI, the “why we process it” column is our specified purpose of use, and we will not use your personal information beyond it without your consent. Where a basis is consent, you can withdraw it at any time (see section 8) without affecting processing that already took place.
| Data | Why we process it | Legal basis (Thai PDPA) |
|---|---|---|
| Camera frames and derived visual features — images from your rear camera while AR navigation is on, and the mathematical feature descriptors extracted from them | To compute where you are and which way you are facing, so we can draw AR directions onto the floor in front of you | s.19 consent |
| Indoor position, heading and floor level | To place you on the venue map, route you, and switch floors correctly | s.24(3) contractual necessity |
| Coarse device location and GPS — used at the edges of a venue and to work out which venue you are in | To select the right venue map and to hand over between outdoor and indoor positioning | s.19 consent |
| Navigation activity — search terms, chosen destination, route requested, route followed, arrival, and whether you asked for a step-free route | To deliver directions, to correct wrong or stale map data, and to see which routes fail so we can fix them | s.24(3) contractual necessity; s.24(5) legitimate interest |
| Accessibility preference — if you turn on step-free routing (see section 6) | To route you away from stairs and escalators. Never used for advertising | s.26 explicit consent |
| Saved places — your parking spot and any place you bookmark | To let you walk back to your car or a saved spot | s.24(3) contractual necessity |
| Account data — email address, display name, sign-in identifier, and the identifier supplied by Apple, Google or another sign-in provider if you use one | To create and secure your account and sync saved places across your devices. Optional — navigation works without an account | s.24(3) contractual necessity |
| Device and technical data — device model, operating system version, app version, language and region, camera and sensor capabilities, coarse network information, and a resettable app instance identifier | To make VPS and AR rendering work correctly on your hardware, to keep the Service secure, and to prevent abuse | s.24(5) legitimate interest |
| Diagnostics — crash reports, error logs, positioning failure events, tracking-quality metrics, latency and frame rate | To find and fix crashes and positioning failures | s.24(5) legitimate interest |
| Map improvement data — scanning data (camera frames and visual features, with every person anonymised before storage) and navigation data, retained beyond the positioning request. Governed by the Help improve maps switch | To keep venue maps current, fix drift and gaps, and improve VPS accuracy | s.24(5) legitimate interest, with an unconditional opt-out |
| Advertising data — in-app interaction and navigation history used to select ads, plus ad delivery events such as impressions, clicks and frequency. Governed by the Personalised ads switch (see section 11) | To choose which sponsored places to promote to you based on how you use Graffity Maps, and to measure and cap how often you see them | s.24(5) legitimate interest, with an unconditional opt-out; s.19 consent in markets whose law requires opt-in for this purpose |
| Contextual ad data — the venue and floor you are currently in, the search you just typed, the screen you are on, coarse region and language, and non-identifying delivery data | To promote sponsored places relevant to where you are and what you just searched for, and to fund the free app when you have not enabled personalised ads | s.24(5) legitimate interest |
| Product analytics — which screens and features you use, in aggregate | To understand which features are worth keeping and where people get stuck | s.24(5) legitimate interest |
| Support communications — your messages, contact details and any information you choose to send us | To answer you and keep a record of the issue | s.24(3) contractual necessity; s.24(5) legitimate interest |
| Records required by law — consent records, rights request records, and records of legally required disclosures | To demonstrate compliance and to respond to lawful requests | s.24(6) legal obligation |
Where the table cites legitimate interests, we have weighed our interest against your privacy and concluded that the processing is limited to what is needed, uses the least identifying data that will work, and would be expected by a reasonable user of a free, ad-supported navigation app. You can object to any of it (see section 15), and for map improvement and personalised ads you can object simply by moving the switch in Settings → Privacy. You can ask us for a summary of the balancing assessment by emailing privacy@graffity.tech.
You are never required to give us data, but some data is unavoidable for the Service to function:
This is the part of Graffity Maps with the most privacy at stake, so we set it out in detail.
While AR navigation is active, the app captures frames from your rear camera and extracts visual features — abstract numerical descriptors of corners, edges and textures in the scene. Those features are matched against a prebuilt 3D map of the venue to compute your position and heading. The app is looking at the geometry of the building, not at the people in it.
Depending on your device and the venue, feature extraction and matching happen on your device, on our servers, or split between the two. Where a request is sent to our servers, it contains the camera frame or the features extracted from it, the venue identifier, device sensor readings, and a request identifier — and nothing that identifies you by name.
Before any camera imagery is written to storage, an automated process detects every person in the frame and irreversibly anonymises them — the whole body, not only the face. The anonymisation is applied to the stored image itself and cannot be undone or reversed by us or by anyone else. We do not keep an unmasked original.
The same process removes other details in the frame that could point to a particular person — including vehicle licence plates in car parks, and identifying text such as name badges, documents and screens caught in view. What is left is the building: floors, walls, signage, fixtures and shopfronts.
Pointing a phone down a corridor inevitably catches other people. We have designed the Service to minimise the consequences: features used for positioning are geometric and are not a face template; we do not perform facial recognition or any other biometric identification; and every person in stored imagery is fully anonymised as described above. We do not use camera frames to build biometric identifiers, so we do not process biometric data within the meaning of Thai PDPA s.26 or the APPI. If you believe you appear in imagery we hold, you can still exercise the rights in section 15.
Nothing seen by the camera — the shops you pass, the products on shelves, the people around you — is used to select, target or measure sponsored places, and no camera imagery or visual feature data is shared with any advertiser. Ad selection uses only the data described in section 11.
Graffity Maps does not read your photo library. Camera access is used for the live camera stream only. If a future feature needs photo library access, we will ask for it separately and update this policy first.
The app does not record video or audio. The microphone is not used.
Graffity Maps offers step-free routing for wheelchair users, people with strollers and people with luggage. We recognise that turning this setting on may reveal something about your health or disability. That makes it sensitive personal data under Thai PDPA s.26 and special care-required personal information under the APPI, which we may only collect with your prior explicit consent. We therefore:
We do not ask for, and ask you not to send us, any other sensitive data — including health records, religious or political views, or trade union membership.
Graffity Maps carries advertising, so it is worth being precise about the limits we hold ourselves to:
Two settings in Settings → Privacy inside Graffity Maps control the optional uses of your data. Each can be changed at any time, and a change takes effect immediately for future processing:
Withdrawing consent, or switching off a setting we run on legitimate interests, does not affect the lawfulness of processing that already happened. You can also ask us to delete the data already collected under either setting — see section 15.
The app asks for the minimum permissions it needs, at the moment it needs them:
You can grant or revoke any of these at any time in Settings → Privacy on iOS or Settings → Apps → Permissions on Android. Revoking camera or location permission withdraws the consent we rely on for the corresponding processing; the AR features will stop working, but the rest of the app continues.
We share personal data only with the categories of recipient below, and only as much as each one needs.
All processors act on our documented instructions, are bound by confidentiality, are required to apply appropriate security measures, and may not use your data for their own purposes. A current list of our processors, including their locations, is available on request from privacy@graffity.tech.
Venue operators pay to have their buildings mapped, and they want to know how the building is working. What they receive from us is aggregated and de-identified: for example the number of navigation sessions per day, the most searched destinations, common origin-destination pairs, average walking times, floors where positioning tends to fail, and counts of step-free route requests.
We apply minimum aggregation thresholds so that small counts cannot be traced back to one person, and we do not provide operators with individual trails, device identifiers, camera imagery, account identifiers or contact details. Once aggregated in this way, the statistics are no longer personal data.
If a venue asks you to identify yourself — for example through its own loyalty programme, Wi-Fi login or app — that is the venue's own processing under the venue's own privacy notice, and not covered by this policy.
Graffity Maps is free to use and is funded by advertising. Our ads are sponsored places: a shop, restaurant, service counter or other destination inside a mapped venue can pay to be promoted — appearing higher in search results, or as a promoted pin on the 2D map. This is the model Google Maps uses for promoted businesses.
Depending on your Personalised ads setting, we use one of two sets of signals:
We also record ad delivery events — that a sponsored place was shown, whether it was tapped, and how often you have seen it — so that we can cap repetition and bill advertisers correctly.
Personalisation is on by default, and you can turn it off at any time in Settings → Privacy with no loss of functionality. Turning it off is a single switch, takes effect immediately, and does not require you to contact us or give a reason. We rely on our legitimate interest in funding a free app, and your right to object to that is unconditional.
In any market whose law requires opt-in consent for this kind of processing, the switch starts off instead and we ask for your consent first, in a choice as easy to refuse as to accept. If you refuse, you still see contextual sponsored places and no feature is withheld or degraded.
Turning personalisation off stops us using your history to select sponsored places from that moment on. You can also ask us to delete the advertising history we already hold — see section 15.
Everything we use for advertising comes from your activity inside Graffity Maps. We do not follow you into other companies' apps or websites, we do not buy or ingest data about you from data brokers or other sources, and we do not use cross-app advertising identifiers such as Apple's IDFA or the Android Advertising ID for tracking. Because we do not track you across other companies' apps and websites, we do not ask for App Tracking Transparency permission on iOS.
Advertisers and promoted businesses receive aggregated campaign reporting: how many times their place was shown, how many people tapped it, how many started navigating to it, and broad breakdowns such as day and venue. They do not receive your identity, contact details, device identifiers, position trail, camera imagery or any list of individuals. We do not sell your personal data to them or to anyone else.
Sponsored places are sold, chosen, served and measured entirely by Graffity, on our own systems. Graffity Maps contains no third-party advertising, measurement or mediation SDK. No advertising network, ad exchange, demand-side platform or data broker receives your data, and none of them runs code inside the app. Your advertising data stays within Graffity and is used only to choose and cap the sponsored places you see.
We do not sell your personal data, and we make none of it available for anyone else to buy.
Each sponsored place carries an option to see why it was shown to you and to change your advertising settings from that point in the app.
We do not knowingly use personalised advertising for anyone below the age at which they can consent on their own under their local law (see section 17). Where we know or reasonably believe a user is below that age, only contextual sponsored places are shown.
In neither case is your personal data stored in Thailand, even though Graffity Technologies Co., Ltd. is established there.
[[CONFIRM — this one materially changes the section below. Can Graffity staff or systems outside the storage country reach this data: (a) can staff in Thailand access personal data held in the Japan or Singapore region, through an admin console, support tool or production database; and (b) does anything holding personal data move between the Japan and Singapore regions, such as shared analytics, backups or model training? If either is yes for Japan, APPI Article 28 applies after all and the receiving country must be named here.]]
Because personal data collected in Japan stays in Japan, we do not make a cross-border transfer of it, and APPI Article 28 does not apply. Entrusting the storage of personal data to a service provider within Japan is not a provision of personal data to a third party under APPI Article 27(5)(i), so we do not need your consent for it. Our provider acts on our instructions only, may not use your data for its own purposes, and is bound by written data protection terms. If this ever changes — if we need to store or access Japanese users' personal data outside Japan — we will update this policy and put an Article 28 basis in place before we do.
If you are outside Singapore, storing your data in Singapore is a cross-border transfer, and we apply these safeguards:
Our cloud providers act as our processors in both regions. They store and serve the data on our instructions, may not use it for their own purposes, and are bound by written data protection terms. We will name the provider for your region, and give you details of the safeguards that apply to a specific transfer, on request to privacy@graffity.tech.
We keep personal data only as long as we need it for the purpose we collected it for, then delete or irreversibly anonymise it. Our standard periods are:
| Data | Retention | Why |
|---|---|---|
| Camera frames and features sent for positioning | Deleted after the request, and in any case within 24 hours | Only needed to answer the positioning request and diagnose failures |
| Map improvement imagery (anonymised; Help improve maps on) | Up to 24 months, or until you switch the setting off | Venue layouts change; maps need periodic revision |
| Position and route history linked to your account | 13 months, then aggregated or deleted | Enough to diagnose recurring routing problems across a full year of venue changes |
| Search terms and navigation events not linked to an account | 13 months | Service quality analysis |
| Advertising history used for personalisation | 13 months, or until you switch Personalised ads off or ask us to delete it | Keeps promotion relevant without holding a long-term profile |
| Ad delivery and billing records (impressions, taps, frequency) | Aggregated within 90 days; aggregated billing records kept as required for tax and accounting | Billing advertisers accurately and capping repetition |
| Accessibility preference | Until you change it or delete your account; deleted within 30 days of either | It is a live setting, not a history |
| Saved places, including your parking spot | Stored on your device until you delete it; parking spots auto-expire after 7 days. If synced to an account, deleted within 30 days of deletion or account closure | You control your own saved places |
| Account data | For the life of the account, then deleted within 30 days of closure | Needed to operate the account |
| Crash reports and diagnostic logs | 90 days | Long enough to reproduce and fix a defect |
| Security and access logs | 12 months | Incident investigation and abuse prevention |
| Product analytics | 25 months, then aggregated | Year-on-year comparison |
| Support correspondence | 24 months after the case closes | Handling repeat and related issues |
| Consent, setting-change and rights-request records | As long as required by applicable law, and at least 3 years | Demonstrating compliance |
| Records needed for legal claims, tax or accounting | As required by the applicable limitation or statutory period, up to 10 years in Thailand | Legal obligation and defence of claims |
Aggregated and irreversibly anonymised statistics — which cannot be linked back to you — may be kept indefinitely. Backups are overwritten on a rolling cycle, so deleted data may persist in encrypted backups for a short period after deletion from live systems before being purged.
We apply technical and organisational measures appropriate to the risk, including:
If a personal data breach occurs, we will report it to the regulators that require it and tell affected users where the law requires or the risk warrants it. In particular we will notify:
No system is perfectly secure. Please keep your device locked and your account credentials private, and tell us at privacy@graffity.tech if you believe your account has been compromised. Security researchers can report vulnerabilities to the same address.
Subject to the conditions and exemptions in the law that applies to you, you have the right to:
Email privacy@graffity.tech with the request you want to make. Some requests can be completed in the app: you can change both privacy switches in Settings → Privacy, edit or delete saved places and your accessibility preference in app settings, and delete your account from Settings → Account → Delete account.
We will:
If you do not use an account, we may hold no data that can be linked to you. In that case we will say so, and explain what you could provide to let us locate your records — but we will not collect extra data about you solely to search for you.
Requests may be made by an authorised representative, on evidence of their authority.
We process personal data as a Data Controller under the Thai PDPA. Our Data Protection Officer can be reached at privacy@graffity.tech. You may complain to the Office of the Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society (pdpc.or.th).
We act as a personal information handling business operator under the APPI. The purposes of use of your personal information are the “why we process it” entries in section 4, and we will not use your personal information beyond them without your consent. We do not provide your personal data to third parties for their own purposes, and we do not operate an opt-out third-party provision scheme. Personal data collected in Japan is stored and processed in Japan, as set out in section 12, so it is not transferred out of the country. You have the rights of disclosure, correction, addition, deletion, cessation of use and cessation of third-party provision in respect of retained personal data, exercisable through privacy@graffity.tech. Complaints may be made to the Personal Information Protection Commission (ppc.go.jp).
We comply with the Singapore PDPA, including the Consent, Purpose Limitation, Notification, Access and Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation and Accountability obligations. Complaints may be made to the Personal Data Protection Commission (pdpc.gov.sg).
We comply with the Malaysia PDPA and its principles, including the General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access principles. Complaints may be made to the Personal Data Protection Department (JPDP) (pdp.gov.my).
Where Graffity Maps is available in Indonesia, the Philippines, Vietnam, Taiwan, South Korea or elsewhere, we process personal data in accordance with the applicable local data protection law, including local rights of access, correction and deletion and local breach notification duties. Contact privacy@graffity.tech for jurisdiction-specific details.
Graffity Maps is not directed at children. We do not knowingly collect personal data from:
We do not knowingly show personalised advertising to anyone below the applicable age. Where we know or reasonably believe a user is below it, only contextual sponsored places are shown.
If you are below the applicable age, please use Graffity Maps only with a parent or guardian's involvement. If we learn that we hold personal data collected from a child without the required consent, we will delete it promptly. Parents and guardians can contact privacy@graffity.tech to review or delete a child's data.
Graffity Maps runs automated processing to do its job — computing your position from camera imagery and calculating routes. Those computations affect the directions you see, and nothing else.
Where personalised ads are enabled, we build a limited profile of your in-app activity and use it to decide which sponsored places to promote to you. You can stop it at any time by switching the setting off. It affects which promotions you see and nothing more. We make no decisions based solely on automated processing that produce legal effects or otherwise significantly affect you.
A safety note, not a privacy one: AR directions are guidance, not a substitute for paying attention. Watch where you are walking, obey venue signage and staff instructions, and do not rely on the app in an emergency. See our AR safety guidance.
We may update this policy as the Service changes or the law does. When we do, we will update the version number and the “Last updated” date at the top of this page and post the new version here.
If a change materially affects how we use your personal data, we will give you notice before it takes effect — in the app, by email if we have your address, or both. Where a change requires your consent, we will ask for it and will not rely on the change until you give it. We keep previous versions and can send you one on request.
Questions, rights requests and complaints about privacy:
We would like the chance to put things right first, so please come to us before escalating. But you do not have to: you always have the right to complain directly to your data protection authority, and where the law allows, to seek a judicial remedy. The relevant authorities for the main markets are listed in section 16.