Skip to main content

Privacy Policy

Table of Contents

  1. Who we are

MiOON is a multilingual classifieds marketplace for real estate and services, operating primarily in Phuket, Thailand, with plans to expand across South-East Asia. We operate the website and applications available at mioon.com and related subdomains (the "Platform").

Data controller of your personal data:

  • Legal entity:

  • Registered address:

  • Privacy contact: legal@mioon.com

  • Data Protection Officer (DPO):

If you are a resident of Thailand, we process your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (the "PDPA"). If you are a resident of the European Economic Area, we apply equivalent principles drawn from the General Data Protection Regulation (EU Regulation 2016/679) (the "GDPR"). If you are a citizen of the Russian Federation whose data we process, we comply with the applicable provisions of Federal Law No. 152-FZ "On Personal Data" (the "152-FZ") to the extent it applies.

This policy is published in English (primary language), Russian, and Thai. In the event of discrepancies between versions, the Thai version prevails for residents of Thailand, and the English version prevails for all other readers, unless applicable law requires otherwise.

  1. Definitions

For clarity in this policy:

  • "Personal Data" means any information relating to an identified or identifiable natural person (see [PDPA §6] and Art. 4(1) GDPR).

  • "Processing" means any operation performed on personal data: collection, recording, storage, use, disclosure, deletion, or destruction (see [PDPA §6] and Art. 4(2) GDPR).

  • "Data Subject" means the natural person to whom the personal data relates.

  • "Controller" means the entity that determines the purposes and means of processing. MiOON is the Controller with respect to the personal data described in this policy.

  • "Processor" means the entity that processes personal data on behalf of the Controller (see Section 5).

  • "Listing" means a classifieds advertisement posted on the Platform.

  • "Seller", "Buyer" — user roles defined in our Terms of Service.

  1. What personal data we collect

We collect only personal data that is reasonably necessary for the operation of the Platform. We do not collect:

  • ❌ Government identifiers (passport numbers, tax ID, Thai ID)

  • ❌ Payment data (bank cards, accounts) — payments are not processed on MVP

  • ❌ Medical data

  • ❌ Biometric data

  • ❌ Data of persons under 18 years of age (see Section 10)

  • ❌ Email addresses on MVP —

#CategoryWhen collectedWhat it includes
3.1.1Phone number (E.164 format)At registration and each loginMobile number to which we send a one-time code (OTP) and which, at your choice, may be displayed in the Listing as a contact channel
3.1.2OTP code (6 digits, ephemeral)At registration, login, verificationTemporary numeric code sent by SMS; valid for a short period (typically 5 minutes) and immediately destroyed after use
3.1.3Display name / name (optional)When filling in the profileDisplay name may be a real name, pseudonym, company name, or other text label that the user themselves specifies in the profile. We do not require the display name to match the user's passport data.
3.1.4Alternative messengers (optional)When added in profile settingsTelegram, WhatsApp, LINE identifiers that you have chosen to show as contact channels in the Listing
3.1.5Listing contentWhen posting a ListingText descriptions, prices, locations, photos, structured attributes (number of bedrooms, area, etc.) that you enter. Users must not upload property documents, passports, ID cards, bank documents, contracts, PDF files, or other documents containing personal data or confidential information unless the Platform has specifically requested such data.
3.1.6Contact visibility settingsWhen posting a ListingWhether your contact is publicly visible, visible to authenticated users only, or available on request
3.1.7Favourites and saved searchesWhen adding Listings to favouritesIdentifiers of Listings you have marked; saved search parameters
3.1.8Reports on other ListingsWhen submitting a report to moderatorsListing identifier and reason for the report

3.1. Data you provide directly

3.2. Automatically collected data

#CategoryWhen collectedWhat it includes
3.2.1IP addressOn each request to the PlatformThe address from which you connect; used for rate-limiting, security, regional content delivery
3.2.2User-agentOn each requestBrowser and device identifier transmitted by the browser
3.2.3Cookies and session tokensAt login and during the sessionSee Section 9 and the Cookie Policy
3.2.4Approximate location (regional)On each requestDetermined by IP address only; used for default language and currency. We do not collect precise GPS coordinates unless you explicitly enter them when posting a Listing
3.2.5Product analytics eventsDuring Platform usePages viewed, clicks, search queries, time spent on Listings; linked to a pseudonymous identifier (not your phone number)
3.2.6Error reportsWhen the application crashesDiagnostic context (URL, browser, anonymised stack trace) sent to the error tracking system; personal identifiers are automatically removed before transmission
3.2.7Session recording — admin/moderator routes onlyWhen staff are active on /admin/*Technical session recording and error reproduction. In certain cases we may use technical diagnostic tools, including Sentry Replay, to reproduce errors and improve Platform stability. Such tools are used with text content masking and media blocking to reduce the risk of personal data entering diagnostic records. This data is used for debugging, security, and improving Platform quality.

3.3. Data from third-party sources

#SourceWhat we receivePurpose
3.3.1Tilda (predecessor, shutdown 2026-06-30)Migrated Listings originally published on TildaPreserving marketplace content continuity. Migrated Listings are linked to an internal migration account until the original publisher confirms ownership via OTP. See Section 4.6.
3.3.2Data received from field data collection specialistsListing content collected on behalf of the SellerA service for Sellers who prefer offline interaction. The Seller is the data subject; the Seller confirms publication via OTP sent to their own phone. See Section 4.7.

3.4. Data we intentionally do not collect (sensitive categories)

We intentionally do not collect special categories of personal data as defined in [PDPA §26] and Art. 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sexual orientation. If you voluntarily include such information in the free text of a Listing, you do so at your own initiative; we do not process it as sensitive data separately. We nonetheless recommend against doing so.

Pursuant to [PDPA §19–§24] and Art. 6 GDPR we must have a legal basis for processing your data. The bases we rely on are listed below.

4.1. Managing your account (basis: performance of a contract — [PDPA §24(3)] / Art. 6(1)(b) GDPR)

We process your phone number, OTP, display name, and optional messengers to register, authenticate, post, and manage Listings, and to provide the marketplace service in general. Without this processing we cannot give you access to the Platform.

4.2. Phone OTP authentication (basis: performance of a contract and our legitimate interest in security — Art. 6(1)(b) and 6(1)(f) GDPR)

We send a one-time code by SMS to your phone, store a temporary hash of the code, and compare it with what you entered. Delivery is via a third-party SMS gateway in Thailand (see Section 5). OTP codes are deleted from systems within minutes of expiry.

4.3. Displaying Listings to other users (basis: performance of a contract — Art. 6(1)(b) GDPR)

When you publish a Listing, its content (including the contact channels you choose) is shown to other Platform users. You control which channels (phone, Telegram, WhatsApp, LINE) are visible, and to whom (everyone, authenticated users only, or on request).

4.4. Moderation, fraud prevention, Platform security (basis: legitimate interest — [PDPA §24(5)] / Art. 6(1)(f) GDPR)

We analyse Listings, IP addresses, posting patterns, and user reports to detect duplicate accounts, fraudulent Listings, prohibited content (see Terms of Service), and Platform abuse. We balance this interest against your privacy by minimising the data used and applying pseudonymisation where possible.

4.5. Analytics and product improvement (basis: legitimate interest — Art. 6(1)(f) GDPR; for Thailand residents additionally — consent as a precautionary measure — [PDPA §24(1)])

For residents of Thailand we additionally request consent via a cookie banner on the first visit (see Section 9 and Cookie Policy). You may withdraw consent to analytics at any time — this does not affect your ability to use the Platform.

4.6. Migration from Tilda (basis: legitimate interest with transitional measures — Art. 6(1)(f) GDPR)

Listings originally published on our predecessor (Tilda) are migrated to MiOON until 2026-06-30, when Tilda shuts down. Migrated Listings are linked to an internal migration account and do not display the original publisher's personal contacts until they confirm ownership via OTP. We hold the original publisher's phone number (where we have it) solely for this purpose. If a Listing is not confirmed within 6 months, it is subject to review for deletion.

4.7. (Sellers are data subjects; — our agents)

When a specialist collects a Listing on behalf of the Seller, the Seller is the data subject. The specialist cannot publish the Listing until the Seller confirms via OTP sent to their own phone. The controller of the collected data is MiOON, not the individual specialist. Specialists are bound by internal confidentiality and data processing obligations.

4.8. Automatic translation of Listings (basis: performance of a contract — Art. 6(1)(b) GDPR)

We do not transmit your phone number or other identifiers. Moderators may correct translations.

On data status. The translated text is a derivative of the original Listing content. We retain translations for the same period as the source content (see Section 7).

4.9. Legal obligations (basis: compliance with the law — [PDPA §24(6)] / Art. 6(1)(c) GDPR)

We may process and retain data where required by applicable Thai law, a court order, or a regulatory request (for example, mandatory records in the event of a reported incident or a law enforcement request).

  1. Sub-processors and third-party services

We engage the following service providers ("sub-processors") to process personal data on our behalf. Each is bound by contractual obligations regarding confidentiality, security, and purpose limitation. Where a sub-processor is located outside Thailand, transfers are governed as set out in Section 6.

#ProviderFunctionProcessing regionData categories
5.1Supabase (Supabase, Inc., USA — managed PostgreSQL)Database hostingSingaporeAccounts, Listing content, structured profile data
5.2Railway (Railway Corp., USA — backend hosting)Server-side computeSingapore (asia-southeast1-eqsg3a)Transit request data, server-side processing
5.3Vercel (Vercel, Inc., USA — frontend hosting)Web hosting, image optimisation, edge cacheSingapore edgeHTTP request metadata, optimised images
5.4Cloudflare (Cloudflare, Inc., USA — CDN/WAF)Content delivery, security, DDoS protectionGlobal edgeIP addresses, request metadata, anti-bot signals
5.5Cloudflare R2Object storage for photos and mediaOne configured regionListing photos and media
5.6Upstash (Upstash, Inc., USA — managed Redis)Cache, OTP storage, session mappingSingaporeEphemeral OTP codes (TTL ≤ 5 min), session tokens
5.7Sentry (Functional Software, Inc., USA)Error tracking and performance monitoringUSA or EU (configurable)Anonymised error context; PII scrubbing before transmission
5.8PostHog (PostHog Inc., USA)Product analytics and (admin-only) session recordingEU (default region)Pseudonymous behavioural events; session recording on admin routes only
5.9Axiom or BetterStackServer log aggregation (30 days)USA/EUServer logs
5.10MapTilerVector map tilesMulti-region CDNTile requests (by IP)
5.11Automatic translation service — one of DeepL (Germany), OpenAI (USA), DeepSeek (China)Auto-translation of Listing textProvider's regionListing text only — no user identifiers
5.12SMS gateway — Thai domestic (final choice from ThaiBulkSMS, SMS2Pro, DeeSMSx)OTP deliveryThailandPhone number, OTP code

We update this list when a sub-processor is added, removed, or replaced. The current list is always available at this URL. We notify of material changes as described in Section 11.

  1. International data transfers

Most of your data is stored in Singapore (Supabase, Railway, Upstash) — we chose this region to keep data within South-East Asia and close to most users. However, some sub-processors inevitably operate in other regions:

  • Sentry (USA or EU) — anonymised error reports

  • PostHog (EU by default) — pseudonymous analytics

  • Translation service (provider's region) — Listing text

  • Cloudflare and MapTiler — global edge

  • R2 object storage — region per configuration

Pursuant to [PDPA §28], transferring personal data abroad requires that the destination country provide an adequate level of protection, or that one of the established bases applies (consent, performance of a contract, contractual safeguards). For each sub-processor we rely on either:

  • A jurisdiction recognised by the Thai Personal Data Protection Committee (PDPC) as providing adequate protection [PDPA §28(1)]; or

  • Contractual safeguards — typically Standard Contractual Clauses or equivalent vendor DPAs [PDPA §28(2)] / Art. 46 GDPR.

Copies of the applicable safeguards can be requested via the contacts in Section 12.

  1. Retention periods

We retain your personal data only for as long as necessary for the purposes of collection, plus any period required by applicable law.

CategoryPeriod
Profile data (phone, name, messengers)For the lifetime of the account plus 1 year after deletion — for resolving disputes and complaints, then permanent deletion
OTP codesUp to 5 minutes in cache, then destruction
Active Listing (text, photos)For the lifetime of the Listing plus 3 years after expiry/deletion — for audit and dispute resolution
"Contact initiation" events (identifiable form)6 months in identifiable form, then anonymised aggregate for up to 2 years
Listing reportsUntil resolved, plus 1 year
Server logs (Axiom / BetterStack)30-day rolling window
Error reports (Sentry)Per Sentry defaults
Analytics events (PostHog)Configurable; default 1 year, then aggregation/anonymisation
Admin session recordings (PostHog)30 days
IP addresses in logs30 days
CookiesSee Section 9 and Cookie Policy

Where law requires longer retention (court order, regulatory request, ongoing proceedings), we extend the period only for the affected data and only for the time required.

  1. Your rights as a data subject

You have the following rights with respect to your personal data. These derive from [PDPA §30–§36] and Arts. 15–22 GDPR.

8.1. Right to be informed

You have the right to clear information about how we process your data. This policy is our primary disclosure.

8.2. Right of access

You may request a copy of the personal data we hold about you.

8.3. Right to rectification

You may correct inaccurate or incomplete data. Most fields are editable in the profile and Listing settings; for non-user fields, write to us.

8.4. Right to erasure ("right to be forgotten")

8.5. Right to restriction of processing

You may ask us to suspend processing while a question of accuracy or lawfulness is being resolved.

8.6. Right to data portability

You may request a machine-readable export (JSON) of data you have provided. We will deliver it within the timeframe of Section 8.10.

8.7. Right to object

You may object at any time to processing based on legitimate interest, especially analytics. The easiest way is to decline analytics cookies in the banner; you may also write to us. Objecting does not affect your ability to use the Platform.

8.8. Right to withdraw consent

Where the basis is your consent (e.g. analytics cookies for Thailand residents), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

8.9. Right not to be subject to solely automated decision-making

On MVP, MiOON applies automated routing of Listings into moderation queues (e.g. prioritising suspected fraud). We do not reject Listings or block accounts automatically; any adverse decision is reviewed by a human moderator. If this practice changes, we will update the policy and request consent where required.

8.10. How to exercise your rights

Send a request to legal@mioon.com from the phone number linked to your account, or provide sufficient information to verify your identity. Response timelines:

  • Within 30 days of receipt for access, portability, rectification, erasure requests [PDPA §30(3)] / Art. 12(3) GDPR;

  • Within a reasonable time and at the earliest opportunity for objections and restrictions.

If we need more time, we will notify you within the initial 30-day period with an explanation.

The first request within a 6-month period is free. We reserve the right to charge a reasonable fee for manifestly unfounded or repetitive requests ([PDPA §30(4)] / Art. 12(5) GDPR).

8.11. Right to lodge a complaint

If you believe we have processed your data unlawfully, you may contact the Thai Personal Data Protection Committee (PDPC). Contact details — Section 12.

  1. Cookies and similar technologies

We use cookies and similar technologies for authentication, functionality, and analytics. The full list of cookies — names, purposes, durations, first-party vs third-party, effect of blocking — is set out in the separate Cookie Policy.

Strictly necessary cookies (authentication, CSRF protection, language setting) are set by default and cannot be disabled without losing core functionality.

  1. Minors' data

The Platform is intended solely for persons aged 18 and over. We intentionally do not collect data from persons under 18. If you believe a minor has provided us with data, write to legal@mioon.com — we will promptly delete it. We do not require age verification at login, but creating an account in breach of the 18+ requirement is a violation of the Terms of Service.

  1. Changes to this policy

We may update the policy. For material changes — such as adding a new sub-processor that materially changes the processing location, expanding data categories, or introducing automated decision-making — we will:

  • Update the "Last updated" date at the beginning of the document;

  • Notify you in the application at your next login;

  • Publish a summary of changes for at least 30 days after the effective date.

Minor changes (typos, clarifications, restructuring) may be made without notice, but are always reflected in the "Last updated" date.

Previous versions are retained and available on request.

  1. How to contact us and where to complain

MiOON contacts

  • Email: legal@mioon.com

  • In the application: privacy contact form in account settings

Complaint to the Thai PDPC

The Personal Data Protection Committee is the supervisory authority in Thailand. Published contact details:

EEA residents

If you are in the EU/EEA, you have the right to contact your national data protection authority. Directory: https://edpb.europa.eu/about-edpb/about-edpb/members_en.

Russian Federation residents

If 152-FZ applies to the processing of your data, you may contact Roskomnadzor (Federal Service for Supervision of Communications, Information Technology, and Mass Media) — https://rkn.gov.ru/.