CITY PASSPORT · INTELLIGENT CITY TOURISM
Privacy Notice
This Notice explains how City Passport collects, uses, stores and discloses personal data when visitors use authentication, discovery, routes, check-ins, saved journeys, achievements and rewards.
1. Data controller and scope
City Passport is an Intelligent City Tourism / Connected Experience Platform. The organization that determines the purposes and means of processing for the specific deployment should be identified as the data controller. Radical Enlighten may act as platform operator, service provider and/or processor depending on the project arrangement.
Privacy contact: info@radical-enlighten.com
2. Personal data we may collect
- Account data: email, display name, visitor ID and verification status.
- Authentication/security data: magic-link metadata, session identifiers, login times, security events and technical network/browser data where logged.
- Travel/preferences: favorites, saved/liked trails, selected places, route preferences, travel mode and planning choices.
- Activity/location-related data: check-ins, place, time, QR verification and location/distance when required by a feature.
- Achievement/reward data: badge progress, achievements, coupons, claim codes, QR redemption, merchant/place and redemption time.
- Technical data: cookies, session state, server/error logs and usage events necessary to operate and secure the service.
3. How data is collected
Data may be provided directly by you, generated automatically during use, or received from participating places, merchants, mapping/routing/transport services and project systems where necessary for a requested feature.
4. Purposes and typical lawful basis
| Purpose | Data examples | Typical basis |
|---|---|---|
| Authentication and Passport session | Email, visitor ID, session/security data | Contract/user request; legitimate security interests |
| Journey saving, recommendations and personalization | Favorites, trails, preferences, planning choices | Contract/service requested; legitimate interests where appropriate |
| Check-in verification and rewards | Place/time, QR/location verification, badges/coupons | Service operation; legitimate fraud-prevention interests |
| Security, troubleshooting and improvement | Logs, device/browser, security events | Legitimate interests; legal obligations where applicable |
Where a specific optional activity legally requires consent, consent should be requested separately and may be withdrawn without affecting prior lawful processing.
5. Cookies and 7-day login
After successful email verification, the current browser may remain authenticated for up to 7 days. The state may end earlier if you sign out, delete cookies/site data, change browser/device, or the session is invalidated for security.
6. Sharing and disclosure
- Authorized project administrators and technical operators.
- Hosting, email, security, mapping, routing or infrastructure providers under appropriate terms.
- Participating merchants/places only to the extent needed to validate or redeem a reward.
- Authorities or other parties where required by law or necessary to protect security and rights.
City Passport does not intend to sell personal data for advertising purposes.
7. International transfers
If service providers process personal data outside Thailand, the controller should assess the transfer and implement safeguards required by applicable law.
8. Retention
- Authentication session: designed for up to 7 days after successful verification on the current browser.
- Passport account/journey records: retained while needed to provide requested collections and services, subject to deletion/anonymization and legal requirements.
- Coupon/redemption and security records: retained as reasonably necessary for validation, disputes, fraud prevention, audit and legal obligations.
9. Security
Appropriate safeguards should include access control, secure authentication, least privilege, logging, secure transport, backups and incident management proportionate to risk.
10. Your privacy rights
Subject to applicable law and conditions, you may request access/copy, correction, deletion or anonymization, restriction, objection, portability, withdrawal of consent where consent is the basis, and may lodge a complaint with the competent authority.
Requests: info@radical-enlighten.com. Identity verification may be required.
11. Children and supervised use
If a deployment is offered directly to minors, the controller should implement age-appropriate notices and any consent/authorization procedure required by applicable law.
12. Changes and contact
This Notice may be updated when features, project roles, legal requirements or data practices change. Material changes should be communicated through an appropriate channel.
