City Passport

CITY PASSPORT · INTELLIGENT CITY TOURISM

Privacy Notice

This Notice explains how City Passport collects, uses, stores and discloses personal data when visitors use authentication, discovery, routes, check-ins, saved journeys, achievements and rewards.

Effective 19 August 2026passport.smartcit.com

1. Data controller and scope

City Passport is an Intelligent City Tourism / Connected Experience Platform. The organization that determines the purposes and means of processing for the specific deployment should be identified as the data controller. Radical Enlighten may act as platform operator, service provider and/or processor depending on the project arrangement.

Privacy contact: info@radical-enlighten.com

2. Personal data we may collect

3. How data is collected

Data may be provided directly by you, generated automatically during use, or received from participating places, merchants, mapping/routing/transport services and project systems where necessary for a requested feature.

4. Purposes and typical lawful basis

PurposeData examplesTypical basis
Authentication and Passport sessionEmail, visitor ID, session/security dataContract/user request; legitimate security interests
Journey saving, recommendations and personalizationFavorites, trails, preferences, planning choicesContract/service requested; legitimate interests where appropriate
Check-in verification and rewardsPlace/time, QR/location verification, badges/couponsService operation; legitimate fraud-prevention interests
Security, troubleshooting and improvementLogs, device/browser, security eventsLegitimate interests; legal obligations where applicable

Where a specific optional activity legally requires consent, consent should be requested separately and may be withdrawn without affecting prior lawful processing.

5. Cookies and 7-day login

After successful email verification, the current browser may remain authenticated for up to 7 days. The state may end earlier if you sign out, delete cookies/site data, change browser/device, or the session is invalidated for security.

6. Sharing and disclosure

City Passport does not intend to sell personal data for advertising purposes.

7. International transfers

If service providers process personal data outside Thailand, the controller should assess the transfer and implement safeguards required by applicable law.

8. Retention

9. Security

Appropriate safeguards should include access control, secure authentication, least privilege, logging, secure transport, backups and incident management proportionate to risk.

10. Your privacy rights

Subject to applicable law and conditions, you may request access/copy, correction, deletion or anonymization, restriction, objection, portability, withdrawal of consent where consent is the basis, and may lodge a complaint with the competent authority.

Requests: info@radical-enlighten.com. Identity verification may be required.

11. Children and supervised use

If a deployment is offered directly to minors, the controller should implement age-appropriate notices and any consent/authorization procedure required by applicable law.

12. Changes and contact

This Notice may be updated when features, project roles, legal requirements or data practices change. Material changes should be communicated through an appropriate channel.

Before public launch, verify the exact controller identity, registered address, DPO/privacy contact, processor list, cross-border providers and exact retention schedule against the real deployment.
City Passport · Intelligent City Tourism · Connected Experience Platform