BaanMe Privacy Policy
Effective date: 2026-06-29
1. Introduction and scope
This Privacy Policy explains how [LEGAL ENTITY NAME — registered controller entity, to be confirmed] ("BaanMe", "we", "us", or "our") collects, uses, discloses, transfers, retains and protects personal data when you use the BaanMe consumer property marketplace, including our website at https://baanme.com and our iOS and Android mobile applications (together, the "Service").
BaanMe is a consumer marketplace for browsing and discovering homes to rent or buy in Thailand. It lets you save searches and listings, set up new-match alerts, send enquiries to real-estate agents, message agents in-app, and pay certain property-related utility and telecom bills through a third-party payment provider.
This Policy is issued under the Personal Data Protection Act B.E. 2562 (2019) of Thailand (the "PDPA"). Where you also enjoy rights under other laws (for example, the EU/UK GDPR if you are in the EU/UK, or the PRC Personal Information Protection Law if you are in mainland China), additional protections may apply; [counsel to confirm the operator's position on GDPR/UK GDPR and PIPL overlap].
Data controller. The data controller for the personal data described here is [LEGAL ENTITY NAME — registered controller entity, to be confirmed], a company incorporated in Thailand with its registered office at [REGISTERED OFFICE ADDRESS, Bangkok, Thailand].
Please read this Policy together with our Terms of Service. If you do not agree with this Policy, please do not use the Service.
2. The personal data we collect
We collect the following categories of personal data. Not every category applies to every user; what we collect depends on how you use the Service.
- Account identity and credentials — your name, email address (which must be unique), a securely hashed password, email-verification status, and internal account/session identifiers and tokens. If you use guest/anonymous browsing, an anonymous flag and identifiers that allow your activity to be linked to a real account if you later register.
- Federated sign-in (OAuth) data — where you sign in with Google or Apple: the provider account identifier, OAuth tokens and scopes, and the name/email contained in your provider profile.
- Verification and one-time tokens — email-verification tokens, password-reset tokens, and confirmation/unsubscribe tokens for email alert subscriptions.
- Contact details — phone number, LINE ID, and other messaging/contact identifiers you provide so that agents can reach you or so we can deliver notifications.
- Enquiries to agents — your name, email, phone, LINE ID, the free-text message you send, the property concerned, your language, and the source surface.
- In-app messages and conversations — the content of messages you exchange with agents (text, images, viewing requests, contact cards, location cards), the conversation participants, and read/delivery markers.
- Saved properties, projects and searches — the listings and projects you save, your saved-search queries, and the filters and frequency you set for new-match alert subscriptions.
- Search and query logs — your search terms, an associated session identifier, your user-agent, your IP address, the result metadata, and the language used.
- Profile and uploaded images — your profile picture and any images you upload (for example, images you attach in a conversation).
- Reviews and ratings — where you review an agent, project or area: your display name, rating and review text.
- Financial / bill-payment data (sensitive — see Section 5) — when you use the bill-payment feature: the bill amount and currency, biller code and category, bill reference numbers and barcode, the customer name on the bill, the OCR (text-recognition) output, the scanned bill image, and the payment-provider transaction references (invoice number, charge reference, payment token, hosted-payment-page URL).
- Passport / machine-readable-zone identity data (sensitive — see Section 5) — if you use a document-prefill feature that reads a passport: your name, date of birth, passport number and expiry, sex, nationality, the passport image, and a validity flag. This is collected only with your explicit consent.
- Product-analytics event stream — events describing how you interact with the Service (for example, page or screen views, property views, searches, and contact actions), together with anonymous and account identifiers, session identifiers, the page/path and referrer, your device, screen, locale, timezone and connection information, your IP address (and a hashed form of it), your user-agent (and a parsed form of it), and approximate geolocation (country, region, city). The collection and use of this data is governed by your consent choices (see Sections 4 and 9).
- Marketing attribution and advertising identifiers — campaign parameters (such as UTM tags), advertising click identifiers (such as gclid, fbclid, ttclid), the referrer and landing page, and, on the mobile app, install-attribution data and — only after you grant App Tracking Transparency permission on iOS — your device advertising identifier (IDFA) via our attribution provider.
- Hashed PII for advertising conversion measurement — irreversible (SHA-256) hashes of identifiers such as your email, phone, name and city/country, used to match advertising conversions (see Sections 6 and 8). This occurs only where you have consented.
- Consent and opt-out records — your consent state, the time it was decided, your App Tracking Transparency decision, and analytics opt-out records.
- Push tokens and notification records — your push-notification token, device platform and identifier, and a record of notifications we send you and their delivery status.
- Precise and coarse geolocation — precise device location from your phone's GPS, collected only when you grant the location permission, used for nearby-property search; and coarse location derived from your IP address, used for default region detection and analytics.
- Diagnostics, crash and performance telemetry — crash reports, performance traces, and device/OS information, which may be associated with your account after you sign in.
- AI-derived data — data derived by automated models, such as image classifications/embeddings, bill OCR fields, and passport field extraction (see Sections 5 and 10).
We do not deliberately collect special-category data beyond the identity-document and bill-payment data described in Section 5. Please do not submit sensitive personal data in free-text fields (for example, in enquiries, messages or reviews) unless it is necessary.
3. Where the data comes from
We collect personal data:
- directly from you — when you create an account, complete your profile, submit an enquiry, message an agent, save searches, subscribe to alerts, write a review, upload an image, scan a bill or passport, or contact us;
- automatically — when you use the Service, through your device and our analytics, logging, security and diagnostics systems (for example, IP address, device data, search logs, and event data); and
- from third parties — from Google or Apple when you choose federated sign-in, and from our infrastructure providers (for example, coarse location derived from network/IP data).
4. Purposes of processing and lawful basis
We process personal data only where we have a lawful basis under PDPA section 24 (and, for sensitive data, the explicit consent or exception required by section 26). The lawful bases we rely on are: performance of a contract with you; your consent; our legitimate interests (balanced against your rights and freedoms); and compliance with a legal obligation.
Note for counsel. The lawful bases below are first-pass determinations derived from the code-grounded data inventory. Thailand does not read "legitimate interest" as broadly as the EU; the final per-purpose basis is a legal judgement and must be confirmed. Where consent is the basis, non-essential trackers must not fire before consent is given.
The following table maps each purpose to the data categories used, the lawful basis, and the retention approach.
| Purpose | Data categories | Lawful basis | Retention |
|---|---|---|---|
| Create and secure your account; authenticate you; manage sessions; password reset; link guest activity to your account | Account identity & credentials; OAuth data; verification/one-time tokens | Contract | Until account deletion; soft-deleted then hard-deleted ~30 days after a deletion request. Session/verification tokens expire at their TTL |
| Display listings and let you browse, search, save properties/searches and view projects | Saved properties/projects/searches; search & query logs; coarse geolocation | Contract (saved items); legitimate interest (search quality, debugging) | Saved items until you remove them or delete your account; search logs [retention period — to be confirmed] |
| Deliver your enquiries to listing agents and enable in-app messaging | Enquiries; in-app messages; contact details | Contract; legitimate interest (connecting you with agents) | [retention period — to be confirmed] |
| Operate new-match alert subscriptions and send notifications (push, email double opt-in, LINE) | Saved searches/subscriptions; push tokens & notification records; contact details; consent records | Consent (marketing alerts); contract (service notifications) | Until you unsubscribe or delete your account; push tokens until revoked |
| Provide precise nearby-property search | Precise geolocation | Consent (device permission) | Not stored beyond the session unless tied to a saved action [to be confirmed] |
| Provide the bill-payment feature (scan, OCR, pay via 2c2p, reconcile) | Financial / bill-payment data (sensitive); AI-derived OCR data | Contract; explicit consent for the bill image/identity data | [retention period — to be confirmed] |
| Provide document-prefill from a passport scan | Passport / MRZ data (sensitive); AI-derived extraction | Explicit consent | Until you delete it or delete your account (image in a private store); [exact hard-delete period — to be confirmed] |
| Product analytics, funnel and conversion measurement | Product-analytics event stream; marketing attribution; consent records | Consent (non-essential analytics/advertising); legitimate interest (de-identified aggregate measurement) | Event data [partition retention — undefined in code; to be confirmed]; consent records ~1 year (cookie) |
| Advertising conversion matching and measurement with advertising platforms | Hashed PII for conversions; marketing attribution & advertising identifiers | Consent | Forwarded only when consented; downstream retention governed by each advertising platform |
| Security, fraud prevention, rate-limiting, and bot protection | Account data; search/query logs; IP address; diagnostics | Legitimate interest; legal obligation (security duty) | As long as necessary for security purposes [to be confirmed] |
| Error monitoring, debugging and performance | Diagnostics/crash & performance telemetry | Legitimate interest | As set by our diagnostics provider [to be confirmed] |
| Record and honour your consent and opt-out choices | Consent & opt-out records | Legal obligation; consent | Consent cookie ~1 year; opt-out records retained as the record of your choice |
| Send operational notifications about new signups to our internal team | Account identity (name + email) | [lawful basis — to be confirmed; see Section 8 disclosure] | Held in the third-party messaging channel's history [to be confirmed / restrict or discontinue] |
| Respond to your requests and exercise of rights; comply with legal obligations | Any relevant category | Legal obligation; legitimate interest | As required to handle the request and evidence compliance |
Where we rely on consent, you may withdraw it at any time (Section 11), and withdrawal is as easy as giving consent. Withdrawing consent does not affect processing carried out before withdrawal.
5. Sensitive personal data
Certain data we process is sensitive personal data or identity-document data attracting heightened protection under PDPA section 26. We process it only with your explicit consent (or a narrow lawful exception confirmed by counsel) and apply heightened safeguards.
- Passport / machine-readable-zone identity data — collected only for document-prefill features, only with your explicit consent (each write requires a recorded consent timestamp). The passport image is stored in a private storage bucket that is never made public. You can delete this data on request.
- Bill-payment data, including the scanned bill image — when you use the bill-payment feature, the bill image is stored in the private storage bucket and is processed to extract the payment fields. Bill data is treated as sensitive financial information.
- Identity-document images more generally — where identity verification is offered, selfie and identity-card images are stored in the private storage bucket and access is restricted.
Escalate to counsel. The section-26 basis and classification for identity-document and facial images (including whether any facial image constitutes biometric data), and the explicit-consent capture for each, must be confirmed. China-bound processing of bill images (Section 8) is high-attention.
We do not ask for, and you should not provide, other special categories of data (such as health, religion, or political opinions).
6. Cookies, tracking technologies and mobile tracking
We use cookies and similar technologies on the website, and equivalent SDKs and device mechanisms in the mobile app.
Strictly necessary (always on). These are required for the Service to function and are not subject to consent:
- the session cookie (keeps you signed in);
- OAuth state cookies (protect federated sign-in against CSRF); and
- the consent cookie (records your consent choice; stored for about one year).
Non-essential / consent-gated. These are used only after you accept them and can be declined or withdrawn at any time:
- Product analytics (our first-party analytics and our analytics processor) — including an anonymous analytics identifier and first/last-touch attribution cookies;
- Advertising conversion measurement with advertising platforms (see Section 8); and
- on the website, where applicable, Google Consent Mode wiring for analytics/advertising tags, which defaults to "denied" until you consent.
Before you consent, pre-consent page views are recorded only as a de-identified, daily-rotating per-site visitor count; we do not store your raw IP or user-agent for those anonymous events, and we do not forward them to our analytics processor or to advertising platforms.
Mobile-app tracking and iOS App Tracking Transparency (ATT). On iOS, before any cross-app/cross-site tracking occurs, we present Apple's App Tracking Transparency prompt. Our install-attribution provider and the device advertising identifier (IDFA) are activated only if you grant ATT permission; this is declared as "tracking" in our App Store privacy disclosures. If you deny ATT (or have not yet decided), install attribution and IDFA-based tracking are not used.
You can manage cookies in your browser settings, manage tracking via your device settings (including iOS ATT and Android advertising-ID controls), and change your consent at any time through the in-app/in-site consent controls (Section 11).
7. Automated processing and profiling
We use automated processing in the following ways. None of these produces a legal or similarly significant effect on you, except as flagged for advertising:
- Advertising conversion matching and audience measurement — where you consent, hashed identifiers and behavioural events are shared with advertising platforms to measure conversions and, through those platforms, support audience/retargeting. This is profiling for advertising purposes. You can object by declining or withdrawing advertising consent (and, on iOS, by declining ATT).
- Image classification and similar-listing search — listing images are automatically classified and embedded to group galleries and surface similar listings.
- Bill and passport text extraction (OCR / MRZ) — automated models read your scanned bill or passport to pre-fill fields; you review and confirm before the data is used.
You have the right to object to automated processing as described in Section 12. We do not make solely-automated decisions that produce legal or similarly significant effects on you.
8. Recipients, disclosures and third parties
We share personal data only as necessary for the purposes above. Our recipients fall into the following categories.
Service providers / processors acting on our instructions:
- Cloudflare — object storage of images/documents (including private-bucket sensitive images), CAPTCHA, IP-based geolocation, and CDN/edge services.
- Our product-analytics processor (PostHog) — first-party analytics storage/forwarding (hosted in the United States). For consented users, the data forwarded can include your IP address and approximate geolocation.
- 2c2p — the payment provider that operates the hosted payment page for the bill-payment feature (see Section 9 of the Terms of Service). 2c2p provides a collection facility only.
- Resend — sending transactional and notification emails.
- Sentry — crash, error and performance diagnostics.
- Expo push — delivering mobile push notifications.
- AI/ML providers — for image, OCR and text features, including DashScope / Alibaba Cloud (Qwen) and z.ai / Zhipu (GLM), both processing in China; and OpenRouter, Anthropic and OpenAI (United States). See the China-transfer note below.
- Messaging channels — LINE and, where applicable, WhatsApp, used to deliver notifications or as agent-contact channels.
- Mapping providers — for map rendering and tiles.
Separate controllers that determine their own purposes for the data they receive (we share only with your consent where required):
- Advertising platforms — Meta (Conversions API), Google Ads (Enhanced Conversions) and TikTok (Events API) — receive hashed identifiers, click identifiers and conversion events to measure and optimise advertising, only where you have consented.
- Branch.io — mobile install attribution and deep linking, activated only after ATT permission on iOS.
- Google and Apple — for federated sign-in (and Google additionally for consent-mode/maps), which receive the relevant profile/consent data.
Listing agents and agencies. When you submit an enquiry or message an agent, the personal data in that enquiry/message (name, contact details, message) is disclosed to the relevant agent or agency so they can respond. Those agents/agencies are independent businesses responsible for their own use of your data.
Operational signup notification (disclosed for transparency). Our system currently sends a notification to an internal Telegram channel when a new account is created, which includes the new user's name and email. [This disclosure to a third-party messaging channel is flagged for counsel: confirm the lawful basis, restrict it to the minimum necessary, or discontinue it.]
Other disclosures. We may disclose personal data where required by law, to enforce our Terms, to protect the rights, safety or property of any person, or in connection with a corporate transaction (with appropriate safeguards).
We do not sell your personal data.
Note for counsel. Written Data Processing Agreements (PDPA s.40) with each processor, and the advertising-platform controller relationships, must be confirmed. The existence of signed DPAs/sub-processor agreements could not be determined from the source code.
9. Cross-border transfers
Some of our providers process personal data outside Thailand, including in the United States, China, and Singapore (and potentially other regions). For example: analytics, diagnostics, email, push, advertising and several AI providers are in the United States; bill-image OCR and certain text-embedding processing are carried out by AI providers in China; and payment and certain messaging providers operate in Singapore/Thailand and other regions.
Thailand has no published adequacy ("white") list under the PDPA. We therefore do not rely on an adequacy decision. Instead, we rely on one or more lawful transfer mechanisms under PDPA sections 28–29 for each destination, which may include: your informed consent (after being told that the destination may not provide protection equivalent to Thailand's); necessity for the performance of a contract with you or in your interest; standard contractual clauses (ASEAN Model Contractual Clauses or EU SCCs adapted with Thai-specific obligations, including 72-hour importer breach reporting); or binding corporate rules where applicable.
China transfer — specific notice. When you use the bill-payment feature, the scanned bill image and the text extracted from it are processed by an AI provider in China (for optical character recognition), and certain listing/search text may be embedded by an AI provider in China. China may not provide a level of personal-data protection equivalent to Thailand's, and processing there may also engage China's Personal Information Protection Law (PIPL). [Counsel to confirm the precise transfer mechanism and any PIPL obligations for the China-hosted processing.]
Escalate to counsel. The specific cross-border mechanism for each destination (US, China, Singapore) and each vendor must be selected and documented; do not represent any of these as adequacy-based.
10. AI and machine-learning processing
We use AI/ML to operate certain features: classifying and embedding listing images for gallery grouping and similar-listing search; reading scanned bills (OCR) and passports (MRZ parsing) to pre-fill forms; and supporting search and content features. Some of this processing is carried out by providers located in the United States and China (Sections 8 and 9). You review and confirm any data extracted from your bill or passport before it is used. We do not use your personal data to make solely-automated decisions with legal or similarly significant effects.
11. Your consent and how to withdraw it
Where we rely on your consent — in particular for non-essential analytics, advertising conversion sharing, mobile tracking (ATT/IDFA), precise location, marketing alerts, and the sensitive-data features in Section 5 — that consent is voluntary, and you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Withdrawal is as easy as giving consent. You can:
- change your cookie/consent choices through the consent controls on the website and in the app (which set your consent state to accepted or rejected and stop non-essential trackers);
- change your iOS App Tracking Transparency decision and your device advertising-ID settings in your device settings;
- turn off push notifications in your device settings, and unsubscribe from email alerts via the unsubscribe link or in-app controls; and
- revoke location or other device permissions in your device settings.
If you withdraw consent that is necessary to provide a particular feature (for example, the passport-prefill feature), we may no longer be able to provide that feature.
12. Your rights as a data subject
Under the PDPA (sections 30–36) you have the following rights, subject to the conditions and exceptions in the law:
- Right of access — to be informed of and obtain a copy of your personal data.
- Right to rectification — to have inaccurate or incomplete data corrected. You can edit much of your profile data directly in the Service; for other corrections, contact us.
- Right to erasure — to have your personal data deleted or anonymised. You can delete your account in the Service; deletion is implemented as a soft-delete with a recovery window, followed by a hard delete approximately 30 days later, which cascades to dependent personal data. Passport/identity-document data can be deleted independently on request.
- Right to restriction of processing in certain circumstances.
- Right to data portability — to receive certain data in a machine-readable form, or have it transmitted to another controller, where applicable.
- Right to object to certain processing, including direct marketing and advertising profiling. You can object to analytics/advertising processing by declining or withdrawing consent (and via iOS ATT).
- Right to withdraw consent at any time (Section 11).
- Right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) in Thailand.
How to exercise your rights. Erasure, objection and consent-withdrawal are available through the Service as described above. For access, rectification (beyond self-service edits), restriction, portability, and any other request — these are not self-service features; please contact us at [PRIVACY CONTACT EMAIL — e.g. [email protected]] and we will handle your request. We aim to respond without undue delay and, in any event, within the timeframe required by law (commonly around 30 days). We may need to verify your identity before acting.
13. Data retention
We retain personal data only for as long as necessary for the purposes in Section 4, after which we delete or anonymise it.
- Account data — retained until you request deletion; soft-deleted with a recovery window, then hard-deleted approximately 30 days afterwards.
- Passport/identity-document data — removable on request; otherwise deleted with your account [exact hard-delete period — to be confirmed].
- Consent records — the consent cookie is retained for about one year; your consent state is kept as the record of your choice.
- Session and verification tokens — until they expire (their time-to-live).
- Push tokens — until revoked (on logout or when the device is no longer registered).
- Analytics event data — [retention period for the analytics event store is not yet defined and must be confirmed; the storage-limitation principle requires a defined period or criteria].
- Listings-related enquiries, messages, leads, bill records, reviews and search logs — [retention periods are not yet defined and must be confirmed].
Note for counsel. Retention for several categories is undefined in the codebase. Concrete periods or criteria must be set to satisfy the storage-limitation principle; the bracketed placeholders above must be resolved before publication.
14. Security
We apply organisational and technical measures appropriate to the risk. These include:
- securely hashed passwords and signed session tokens;
- host-only session cookies scoped to our domain, served over HTTPS in production;
- SHA-256 hashing of identifiers before any transmission to advertising platforms;
- a separate private storage bucket for sensitive images (bills, identity documents, passports), which are never made public and are served only through an access-restricted internal proxy;
- an analytics view that excludes raw IP and user-agent, with restricted read access;
- a de-identified, daily-rotating visitor hash for anonymous (pre-consent) events, with raw IP/user-agent not stored;
- an access audit log recording internal access to personal data;
- CAPTCHA on sign-in/sign-up where configured;
- double opt-in for email alert subscriptions;
- application-level rate limiting;
- payment-webhook signature verification with an idempotency ledger, and never trusting return-URL parameters; and
- soft-delete plus a scheduled hard-delete process for account erasure.
All external provider communications use encryption in transit (HTTPS).
We describe only the measures we actually apply. We do not currently represent that data is encrypted at rest, or that multi-factor authentication is enforced; [encryption-at-rest and MFA status are to be confirmed by the operator and added here once verified]. No method of transmission or storage is completely secure.
15. Data-breach handling
If a personal-data breach occurs, we will assess the risk and, where required, notify the PDPC without undue delay and, where feasible, within 72 hours of becoming aware of it (and no later than 15 days where the 72-hour deadline cannot be met, with a justification). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected data subjects without undue delay, with a description of the breach and the mitigation steps. [Counsel to confirm the internal incident-response runbook and the importer 72-hour reporting obligations under any standard contractual clauses.]
16. Children and minimum age
The Service is intended for adults. Our minimum age to use the Service is [MINIMUM AGE — policy decision to be confirmed by counsel] years. [The operator and counsel must decide the minimum-age position and whether an age gate is required; the consumer nature of BaanMe makes this prominent.] We do not knowingly collect personal data from anyone below the minimum age without the consent of a holder of parental responsibility where required by the PDPA. If you believe a person below the minimum age has provided us with personal data, please contact us at [PRIVACY CONTACT EMAIL — e.g. [email protected]] and we will take appropriate steps to delete it.
17. Data Protection Officer
[The operator must decide whether a Data Protection Officer is required under PDPA section 41. Given large-scale behavioural monitoring (analytics and advertising) combined with sensitive-data processing (identity documents and bill data), a DPO obligation is likely.] Where appointed, you may contact our DPO at [DPO / DATA-PROTECTION CONTACT EMAIL — e.g. [email protected]], and the DPO's details will be communicated to the PDPC as required.
18. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Effective date" above and notify you by appropriate means (for example, an in-app or on-site notice, or email where appropriate). Your continued use of the Service after the changes take effect constitutes acknowledgement of the updated Policy, except where additional consent is required by law.
19. How to contact us
- Data controller: [LEGAL ENTITY NAME — registered controller entity, to be confirmed]
- Registered office: [REGISTERED OFFICE ADDRESS, Bangkok, Thailand]
- Privacy contact: [PRIVACY CONTACT EMAIL — e.g. [email protected]]
- Data Protection Officer: [DPO / DATA-PROTECTION CONTACT EMAIL — e.g. [email protected]]
- Website: https://baanme.com
You also have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC), Thailand.
This document is a machine-generated first draft and must be reviewed by a qualified, Thai-licensed lawyer before publication.