Privacy Policy
Table of Contents
- Who we are
MiOON is a multilingual classifieds marketplace for real estate and services, operating primarily in Phuket, Thailand, with plans to expand across South-East Asia. We operate the website and applications available at mioon.com and related subdomains (the "Platform").
Data controller of your personal data:
-
Legal entity:
-
Registered address:
-
Privacy contact: legal@mioon.com
-
Data Protection Officer (DPO):
If you are a resident of Thailand, we process your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (the "PDPA"). If you are a resident of the European Economic Area, we apply equivalent principles drawn from the General Data Protection Regulation (EU Regulation 2016/679) (the "GDPR"). If you are a citizen of the Russian Federation whose data we process, we comply with the applicable provisions of Federal Law No. 152-FZ "On Personal Data" (the "152-FZ") to the extent it applies.
This policy is published in English (primary language), Russian, and Thai. In the event of discrepancies between versions, the Thai version prevails for residents of Thailand, and the English version prevails for all other readers, unless applicable law requires otherwise.
- Definitions
For clarity in this policy:
-
"Personal Data" means any information relating to an identified or identifiable natural person (see [PDPA §6] and Art. 4(1) GDPR).
-
"Processing" means any operation performed on personal data: collection, recording, storage, use, disclosure, deletion, or destruction (see [PDPA §6] and Art. 4(2) GDPR).
-
"Data Subject" means the natural person to whom the personal data relates.
-
"Controller" means the entity that determines the purposes and means of processing. MiOON is the Controller with respect to the personal data described in this policy.
-
"Processor" means the entity that processes personal data on behalf of the Controller (see Section 5).
-
"Listing" means a classifieds advertisement posted on the Platform.
-
"Seller", "Buyer" — user roles defined in our Terms of Service.
- What personal data we collect
We collect only personal data that is reasonably necessary for the operation of the Platform. We do not collect:
-
❌ Government identifiers (passport numbers, tax ID, Thai ID)
-
❌ Payment data (bank cards, accounts) — payments are not processed on MVP
-
❌ Medical data
-
❌ Biometric data
-
❌ Data of persons under 18 years of age (see Section 10)
-
❌ Email addresses on MVP —
| # | Category | When collected | What it includes |
|---|---|---|---|
| 3.1.1 | Phone number (E.164 format) | At registration and each login | Mobile number to which we send a one-time code (OTP) and which, at your choice, may be displayed in the Listing as a contact channel |
| 3.1.2 | OTP code (6 digits, ephemeral) | At registration, login, verification | Temporary numeric code sent by SMS; valid for a short period (typically 5 minutes) and immediately destroyed after use |
| 3.1.3 | Display name / name (optional) | When filling in the profile | Display name may be a real name, pseudonym, company name, or other text label that the user themselves specifies in the profile. We do not require the display name to match the user's passport data. |
| 3.1.4 | Alternative messengers (optional) | When added in profile settings | Telegram, WhatsApp, LINE identifiers that you have chosen to show as contact channels in the Listing |
| 3.1.5 | Listing content | When posting a Listing | Text descriptions, prices, locations, photos, structured attributes (number of bedrooms, area, etc.) that you enter. Users must not upload property documents, passports, ID cards, bank documents, contracts, PDF files, or other documents containing personal data or confidential information unless the Platform has specifically requested such data. |
| 3.1.6 | Contact visibility settings | When posting a Listing | Whether your contact is publicly visible, visible to authenticated users only, or available on request |
| 3.1.7 | Favourites and saved searches | When adding Listings to favourites | Identifiers of Listings you have marked; saved search parameters |
| 3.1.8 | Reports on other Listings | When submitting a report to moderators | Listing identifier and reason for the report |
3.1. Data you provide directly
3.2. Automatically collected data
| # | Category | When collected | What it includes |
|---|---|---|---|
| 3.2.1 | IP address | On each request to the Platform | The address from which you connect; used for rate-limiting, security, regional content delivery |
| 3.2.2 | User-agent | On each request | Browser and device identifier transmitted by the browser |
| 3.2.3 | Cookies and session tokens | At login and during the session | See Section 9 and the Cookie Policy |
| 3.2.4 | Approximate location (regional) | On each request | Determined by IP address only; used for default language and currency. We do not collect precise GPS coordinates unless you explicitly enter them when posting a Listing |
| 3.2.5 | Product analytics events | During Platform use | Pages viewed, clicks, search queries, time spent on Listings; linked to a pseudonymous identifier (not your phone number) |
| 3.2.6 | Error reports | When the application crashes | Diagnostic context (URL, browser, anonymised stack trace) sent to the error tracking system; personal identifiers are automatically removed before transmission |
| 3.2.7 | Session recording — admin/moderator routes only | When staff are active on /admin/* | Technical session recording and error reproduction. In certain cases we may use technical diagnostic tools, including Sentry Replay, to reproduce errors and improve Platform stability. Such tools are used with text content masking and media blocking to reduce the risk of personal data entering diagnostic records. This data is used for debugging, security, and improving Platform quality. |
3.3. Data from third-party sources
| # | Source | What we receive | Purpose |
|---|---|---|---|
| 3.3.1 | Tilda (predecessor, shutdown 2026-06-30) | Migrated Listings originally published on Tilda | Preserving marketplace content continuity. Migrated Listings are linked to an internal migration account until the original publisher confirms ownership via OTP. See Section 4.6. |
| 3.3.2 | Data received from field data collection specialists | Listing content collected on behalf of the Seller | A service for Sellers who prefer offline interaction. The Seller is the data subject; the Seller confirms publication via OTP sent to their own phone. See Section 4.7. |
3.4. Data we intentionally do not collect (sensitive categories)
We intentionally do not collect special categories of personal data as defined in [PDPA §26] and Art. 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sexual orientation. If you voluntarily include such information in the free text of a Listing, you do so at your own initiative; we do not process it as sensitive data separately. We nonetheless recommend against doing so.
- Purposes and legal bases for processing
Pursuant to [PDPA §19–§24] and Art. 6 GDPR we must have a legal basis for processing your data. The bases we rely on are listed below.
4.1. Managing your account (basis: performance of a contract — [PDPA §24(3)] / Art. 6(1)(b) GDPR)
We process your phone number, OTP, display name, and optional messengers to register, authenticate, post, and manage Listings, and to provide the marketplace service in general. Without this processing we cannot give you access to the Platform.
4.2. Phone OTP authentication (basis: performance of a contract and our legitimate interest in security — Art. 6(1)(b) and 6(1)(f) GDPR)
We send a one-time code by SMS to your phone, store a temporary hash of the code, and compare it with what you entered. Delivery is via a third-party SMS gateway in Thailand (see Section 5). OTP codes are deleted from systems within minutes of expiry.
4.3. Displaying Listings to other users (basis: performance of a contract — Art. 6(1)(b) GDPR)
When you publish a Listing, its content (including the contact channels you choose) is shown to other Platform users. You control which channels (phone, Telegram, WhatsApp, LINE) are visible, and to whom (everyone, authenticated users only, or on request).
4.4. Moderation, fraud prevention, Platform security (basis: legitimate interest — [PDPA §24(5)] / Art. 6(1)(f) GDPR)
We analyse Listings, IP addresses, posting patterns, and user reports to detect duplicate accounts, fraudulent Listings, prohibited content (see Terms of Service), and Platform abuse. We balance this interest against your privacy by minimising the data used and applying pseudonymisation where possible.
4.5. Analytics and product improvement (basis: legitimate interest — Art. 6(1)(f) GDPR; for Thailand residents additionally — consent as a precautionary measure — [PDPA §24(1)])
For residents of Thailand we additionally request consent via a cookie banner on the first visit (see Section 9 and Cookie Policy). You may withdraw consent to analytics at any time — this does not affect your ability to use the Platform.
4.6. Migration from Tilda (basis: legitimate interest with transitional measures — Art. 6(1)(f) GDPR)
Listings originally published on our predecessor (Tilda) are migrated to MiOON until 2026-06-30, when Tilda shuts down. Migrated Listings are linked to an internal migration account and do not display the original publisher's personal contacts until they confirm ownership via OTP. We hold the original publisher's phone number (where we have it) solely for this purpose. If a Listing is not confirmed within 6 months, it is subject to review for deletion.
4.7. (Sellers are data subjects; — our agents)
When a specialist collects a Listing on behalf of the Seller, the Seller is the data subject. The specialist cannot publish the Listing until the Seller confirms via OTP sent to their own phone. The controller of the collected data is MiOON, not the individual specialist. Specialists are bound by internal confidentiality and data processing obligations.
4.8. Automatic translation of Listings (basis: performance of a contract — Art. 6(1)(b) GDPR)
We do not transmit your phone number or other identifiers. Moderators may correct translations.
On data status. The translated text is a derivative of the original Listing content. We retain translations for the same period as the source content (see Section 7).
4.9. Legal obligations (basis: compliance with the law — [PDPA §24(6)] / Art. 6(1)(c) GDPR)
We may process and retain data where required by applicable Thai law, a court order, or a regulatory request (for example, mandatory records in the event of a reported incident or a law enforcement request).
- Sub-processors and third-party services
We engage the following service providers ("sub-processors") to process personal data on our behalf. Each is bound by contractual obligations regarding confidentiality, security, and purpose limitation. Where a sub-processor is located outside Thailand, transfers are governed as set out in Section 6.
| # | Provider | Function | Processing region | Data categories |
|---|---|---|---|---|
| 5.1 | Supabase (Supabase, Inc., USA — managed PostgreSQL) | Database hosting | Singapore | Accounts, Listing content, structured profile data |
| 5.2 | Railway (Railway Corp., USA — backend hosting) | Server-side compute | Singapore (asia-southeast1-eqsg3a) | Transit request data, server-side processing |
| 5.3 | Vercel (Vercel, Inc., USA — frontend hosting) | Web hosting, image optimisation, edge cache | Singapore edge | HTTP request metadata, optimised images |
| 5.4 | Cloudflare (Cloudflare, Inc., USA — CDN/WAF) | Content delivery, security, DDoS protection | Global edge | IP addresses, request metadata, anti-bot signals |
| 5.5 | Cloudflare R2 | Object storage for photos and media | One configured region | Listing photos and media |
| 5.6 | Upstash (Upstash, Inc., USA — managed Redis) | Cache, OTP storage, session mapping | Singapore | Ephemeral OTP codes (TTL ≤ 5 min), session tokens |
| 5.7 | Sentry (Functional Software, Inc., USA) | Error tracking and performance monitoring | USA or EU (configurable) | Anonymised error context; PII scrubbing before transmission |
| 5.8 | PostHog (PostHog Inc., USA) | Product analytics and (admin-only) session recording | EU (default region) | Pseudonymous behavioural events; session recording on admin routes only |
| 5.9 | Axiom or BetterStack | Server log aggregation (30 days) | USA/EU | Server logs |
| 5.10 | MapTiler | Vector map tiles | Multi-region CDN | Tile requests (by IP) |
| 5.11 | Automatic translation service — one of DeepL (Germany), OpenAI (USA), DeepSeek (China) | Auto-translation of Listing text | Provider's region | Listing text only — no user identifiers |
| 5.12 | SMS gateway — Thai domestic (final choice from ThaiBulkSMS, SMS2Pro, DeeSMSx) | OTP delivery | Thailand | Phone number, OTP code |
We update this list when a sub-processor is added, removed, or replaced. The current list is always available at this URL. We notify of material changes as described in Section 11.
- International data transfers
Most of your data is stored in Singapore (Supabase, Railway, Upstash) — we chose this region to keep data within South-East Asia and close to most users. However, some sub-processors inevitably operate in other regions:
-
Sentry (USA or EU) — anonymised error reports
-
PostHog (EU by default) — pseudonymous analytics
-
Translation service (provider's region) — Listing text
-
Cloudflare and MapTiler — global edge
-
R2 object storage — region per configuration
Pursuant to [PDPA §28], transferring personal data abroad requires that the destination country provide an adequate level of protection, or that one of the established bases applies (consent, performance of a contract, contractual safeguards). For each sub-processor we rely on either:
-
A jurisdiction recognised by the Thai Personal Data Protection Committee (PDPC) as providing adequate protection [PDPA §28(1)]; or
-
Contractual safeguards — typically Standard Contractual Clauses or equivalent vendor DPAs [PDPA §28(2)] / Art. 46 GDPR.
Copies of the applicable safeguards can be requested via the contacts in Section 12.
- Retention periods
We retain your personal data only for as long as necessary for the purposes of collection, plus any period required by applicable law.
| Category | Period |
|---|---|
| Profile data (phone, name, messengers) | For the lifetime of the account plus 1 year after deletion — for resolving disputes and complaints, then permanent deletion |
| OTP codes | Up to 5 minutes in cache, then destruction |
| Active Listing (text, photos) | For the lifetime of the Listing plus 3 years after expiry/deletion — for audit and dispute resolution |
| "Contact initiation" events (identifiable form) | 6 months in identifiable form, then anonymised aggregate for up to 2 years |
| Listing reports | Until resolved, plus 1 year |
| Server logs (Axiom / BetterStack) | 30-day rolling window |
| Error reports (Sentry) | Per Sentry defaults |
| Analytics events (PostHog) | Configurable; default 1 year, then aggregation/anonymisation |
| Admin session recordings (PostHog) | 30 days |
| IP addresses in logs | 30 days |
| Cookies | See Section 9 and Cookie Policy |
Where law requires longer retention (court order, regulatory request, ongoing proceedings), we extend the period only for the affected data and only for the time required.
- Your rights as a data subject
You have the following rights with respect to your personal data. These derive from [PDPA §30–§36] and Arts. 15–22 GDPR.
8.1. Right to be informed
You have the right to clear information about how we process your data. This policy is our primary disclosure.
8.2. Right of access
You may request a copy of the personal data we hold about you.
8.3. Right to rectification
You may correct inaccurate or incomplete data. Most fields are editable in the profile and Listing settings; for non-user fields, write to us.
8.4. Right to erasure ("right to be forgotten")
8.5. Right to restriction of processing
You may ask us to suspend processing while a question of accuracy or lawfulness is being resolved.
8.6. Right to data portability
You may request a machine-readable export (JSON) of data you have provided. We will deliver it within the timeframe of Section 8.10.
8.7. Right to object
You may object at any time to processing based on legitimate interest, especially analytics. The easiest way is to decline analytics cookies in the banner; you may also write to us. Objecting does not affect your ability to use the Platform.
8.8. Right to withdraw consent
Where the basis is your consent (e.g. analytics cookies for Thailand residents), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
8.9. Right not to be subject to solely automated decision-making
On MVP, MiOON applies automated routing of Listings into moderation queues (e.g. prioritising suspected fraud). We do not reject Listings or block accounts automatically; any adverse decision is reviewed by a human moderator. If this practice changes, we will update the policy and request consent where required.
8.10. How to exercise your rights
Send a request to legal@mioon.com from the phone number linked to your account, or provide sufficient information to verify your identity. Response timelines:
-
Within 30 days of receipt for access, portability, rectification, erasure requests [PDPA §30(3)] / Art. 12(3) GDPR;
-
Within a reasonable time and at the earliest opportunity for objections and restrictions.
If we need more time, we will notify you within the initial 30-day period with an explanation.
The first request within a 6-month period is free. We reserve the right to charge a reasonable fee for manifestly unfounded or repetitive requests ([PDPA §30(4)] / Art. 12(5) GDPR).
8.11. Right to lodge a complaint
If you believe we have processed your data unlawfully, you may contact the Thai Personal Data Protection Committee (PDPC). Contact details — Section 12.
We use cookies and similar technologies for authentication, functionality, and analytics. The full list of cookies — names, purposes, durations, first-party vs third-party, effect of blocking — is set out in the separate Cookie Policy.
Strictly necessary cookies (authentication, CSRF protection, language setting) are set by default and cannot be disabled without losing core functionality.
- Minors' data
The Platform is intended solely for persons aged 18 and over. We intentionally do not collect data from persons under 18. If you believe a minor has provided us with data, write to legal@mioon.com — we will promptly delete it. We do not require age verification at login, but creating an account in breach of the 18+ requirement is a violation of the Terms of Service.
- Changes to this policy
We may update the policy. For material changes — such as adding a new sub-processor that materially changes the processing location, expanding data categories, or introducing automated decision-making — we will:
-
Update the "Last updated" date at the beginning of the document;
-
Notify you in the application at your next login;
-
Publish a summary of changes for at least 30 days after the effective date.
Minor changes (typos, clarifications, restructuring) may be made without notice, but are always reflected in the "Last updated" date.
Previous versions are retained and available on request.
- How to contact us and where to complain
MiOON contacts
-
Email: legal@mioon.com
-
In the application: privacy contact form in account settings
Complaint to the Thai PDPC
The Personal Data Protection Committee is the supervisory authority in Thailand. Published contact details:
-
Office of the Personal Data Protection Committee
-
Website: https://www.pdpc.or.th/
EEA residents
If you are in the EU/EEA, you have the right to contact your national data protection authority. Directory: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Russian Federation residents
If 152-FZ applies to the processing of your data, you may contact Roskomnadzor (Federal Service for Supervision of Communications, Information Technology, and Mass Media) — https://rkn.gov.ru/.