Privacy Policy — Tookpak
⚠️ DRAFT — must be reviewed by a lawyer / PDPA adviser before publication. Written against Thailand's Personal Data Protection Act B.E. 2562 (PDPA). Placeholders:
[legal entity],[contact email],[address],[effective date]. This is a translation of the Thai original; the Thai version prevails in case of conflict.
Effective date: [effective date] · Data controller: [legal entity], [address], [contact email]
1. What we collect
| Type | Examples | Collected when |
|---|---|---|
| Account data | Email, display name, profile photo, cover photo, short bio, language (from Google Sign-In or entered by you) | Sign-up / profile edit |
| Taste profile | Taste quiz answers, ratings you give dishes/places, category preferences, budget, dietary restrictions (e.g. vegetarian, halal)* | Quiz + usage |
| Usage behaviour | Views, agrees, saves, follows, hides, time spent on a post | Using the app/web |
| Content you create | Reviews, photos, ratings, tags, captions | Posting |
| Location | Current coordinates, processed per request only — we do not store your location history | When you allow the "near me" feature |
| Content reports | The reason you pick + any note you type yourself, and the post reported | When you report a post |
| Push notification token | The identifier Firebase issues for your device (not a phone number or email), plus its OS and language | When you allow notifications |
| Technical data | Device model, operating system, error logs | Automatically |
| Crash reports | Stack trace + device model/OS + an installation identifier (not your name or email) | When the app crashes (app only) |
* Some dietary restrictions (e.g. halal) may indirectly indicate religious belief, which is sensitive data under the PDPA. We collect it only when you choose to provide it, use it solely to filter food to your settings, and you can delete it at any time. [lawyer to review: consent basis for sensitive data, s.26]
2. Why we use it (and the legal basis)
- Core service — taste matching: computing "for your taste" recommendations and "likely your taste" scores (basis: performance of contract)
- Public content: reviews and creator profiles are shown publicly, including to search engines, as posted by users (basis: contract)
- Safety and transparency: detecting fake reviews and score manipulation, and reviewing content reports by a person (basis: legitimate interest). We do not disclose to a post's author who reported it.
- Improving the service: aggregate usage analysis (basis: legitimate interest)
- Notifications: telling you about activity on your account (can be turned off in settings)
- We do not sell your personal data.
3. Your taste profile — transparent and under your control
- You can view and edit your taste profile at any time on your profile page (you can retake the quiz).
- Creators only see aggregate statistics about their followers (e.g. "64% like it spicy") — never your individual taste profile.
- Restaurants and sponsors receive no individual-level data.
4. Disclosure to third parties
We share only what is necessary with processors that provide services to us:
- Google Cloud / Firebase (infrastructure, authentication, image storage) — primary servers in the Singapore region [to confirm at provisioning]
- Google Places (restaurant data — your restaurant search terms are sent for processing)
- Google Vertex AI (embeddings — processes review text/tags to build a taste representation; no identifying data is sent)
- Government authorities where required by law
Cross-border transfers (e.g. servers in Singapore) are subject to PDPA safeguards. [lawyer to review: s.28]
5. Cookies and tracking
The website uses strictly necessary cookies (session, theme, language) and aggregate analytics. You can manage these through the cookie banner or your browser settings. Declining analytics stops analytics from being forwarded to any external provider.
6. Retention
- Account data / taste profile / content: for the life of the account
- Account deletion → deleted or de-identified within 30 days (backup copies rotate out within 90 days)
- Raw behavioural logs: kept in account-linked form for no more than 24 months, then only anonymised/aggregated
- Deleted reviews: removed from display immediately
- Content reports: kept for up to 24 months — needed to spot repeat offenders and harassment through false reports [lawyer to review: appropriate period]
- Device notification tokens: deleted when you sign out, turn notifications off, uninstall, or delete your account
7. Your PDPA rights
Access/copy · rectification · erasure · restriction or objection to processing · withdrawal of consent (where consent is the basis) · data portability · complaint to the Personal Data Protection Committee. To exercise: [contact email] — we respond within 30 days. You can also delete your account yourself in the app (Settings → Delete account).
8. Security
Encryption in transit (TLS) and at rest · access limited by role · all secrets held in a secrets manager · in the event of a high-risk data breach we will notify the Office within 72 hours and notify affected individuals as required by law.
9. Minors
The service is not designed for anyone under 13. [lawyer to review: age threshold and parental consent under PDPA s.20]
10. Changes to this policy
Material changes will be announced in-app or by email at least 15 days before they take effect, with a version history.
11. Contact / Data Protection Officer (DPO)
[legal entity] · [address] · [contact email] [lawyer to review: whether a DPO is required given the scale of processing]