EchelonApp
Privacy Policy — Tom Yum

Privacy Policy — Tom Yum

Privacy Policy — Tom Yum

Effective date: 20 May 2026
Last updated: 20 May 2026

This Privacy Policy explains how Echelon Apps Limited («Echelon Apps», «we», «us», or «our»), a company incorporated in Hong Kong SAR, collects, uses, shares, and protects personal data when you use the Tom Yum mobile application (the «App»), including the related backend services and website at https://echelon-app.com/ (together, the «Service»).

Tom Yum helps users discover, rate, review, and save tom yum restaurants in Thailand.

By downloading, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the App.

1. Who is responsible for your data (Data Controller)

The data controller responsible for your personal data is:

Echelon Apps Limited
Hong Kong SAR
Email: manager@echelon-app.com

For any privacy-related request or question, contact us at manager@echelon-app.com.

2. Scope

This Policy applies to personal data we process through the App and Service. It does not apply to third-party services, websites, or restaurants that we do not control, even if they are linked from or integrated with the App (see Section 7).

3. Information we collect

We collect only what we need to operate the App. The categories below reflect what the App actually does today.

3.1 Information you provide

  • Account information. When you create an account we process your email address and, if you sign in with Google, your Google account email and display name (via Google Sign-In). We store an authentication provider type («email» or «google») and an account identifier.
  • Profile information. An optional display name and an optional profile photo (avatar) that you upload.
  • User-generated content. When you write a review we store the rating, the type of tom yum, the approximate visit date (month and year), an optional price level, your optional review text, and any photos you attach.
  • Favorites. The restaurants you save to your «Want to visit» or «Excellent» lists.
  • Reports. If you report a review, we store the reason and a reference to the reported content.

3.2 Information collected automatically

  • Approximate / precise location. With your permission, the App uses your device location to show nearby restaurants and to sort results by distance. If you decline, the App falls back to a default location (Bangkok) and continues to work. Location is processed on your device and in queries to our backend; we do not build advertising profiles from it.
  • Device and technical data. Our hosting and backend provider records standard technical logs (such as IP address, timestamps, and request metadata) for security, abuse prevention, and reliability.

3.3 Guest mode

You can use the App as a guest without an account. In guest mode we generate a local, random device-side identifier stored only on your device. Guests cannot leave reviews or save favorites server-side, and no account-level personal data is created.

3.4 Device permissions

The App may request the following permissions; each is used only for the stated purpose and only after you grant it:

  • Location (while using the App) — to show and sort nearby restaurants.
  • Camera — to take photos for your reviews.
  • Photo Library — to attach existing photos to reviews or set your avatar.

You can change or revoke these permissions at any time in your device settings.

3.5 What we do not collect

  • We do not serve advertising in the App and do not use advertising-tracking SDKs.
  • We do not use third-party analytics, attribution, or tracking SDKs (such as Google Analytics for Firebase, Amplitude, Mixpanel, AppsFlyer, or similar).
  • We do not collect payment-card data (the App has no in-app purchases at this time).
  • We do not knowingly collect data from children (see Section 9).

Note on the in-app consent center. The App includes a privacy consent screen with toggles for «statistical», «functional», and «targeting» data. These controls are provided so that, if we introduce optional analytics or personalization in the future, your stated preferences are respected from day one. As of the effective date above, no statistical, functional-tracking, or targeting data is collected or shared with third parties.

4. How we use your data

We use your data to:

  • create and manage your account and authenticate you;
  • display, store, and let you manage your reviews, photos, ratings, and favorites;
  • show restaurants near you and sort them by distance;
  • operate content moderation and handle reports of inappropriate content;
  • maintain security, prevent fraud and abuse, and debug problems;
  • comply with legal obligations and enforce our Terms of Use.

5. Legal bases for processing (GDPR / EEA & UK users)

Where the EU/UK General Data Protection Regulation applies, we rely on:

  • Performance of a contract — to provide the account and core App features you request.
  • Consent — for device permissions (location, camera, photos) and any future optional analytics/personalization. You may withdraw consent at any time.
  • Legitimate interests — to keep the Service secure, prevent abuse, and improve reliability, balanced against your rights.
  • Legal obligation — where we must process data to comply with applicable law.

6. How we share data

We do not sell your personal data. We share data only with the service providers («sub-processors») that make the App work, and only as needed:

Provider Purpose Data involved
Supabase (database, authentication, file storage) Hosting your account, reviews, photos, favorites; authentication Account data, user content, photos, technical logs
Google (Google Sign-In; Google Places via our server-side proxy) Optional sign-in; restaurant information and photos Google account email/name (sign-in only); restaurant search parameters (no account identifiers are sent to Google Places)
Mapbox (maps and geocoding) Displaying the map and resolving restaurant addresses Coordinates of restaurants; your approximate location when rendering the map
Apple (App Store distribution) App delivery and platform services Governed by Apple’s own privacy policy

We may also disclose data if required by law, to protect our rights or users’ safety, or in connection with a corporate transaction (e.g., merger or acquisition), subject to this Policy.

7. Third-party content and links

Restaurant information, addresses, and some photos are sourced from third-party providers (Google Places, Mapbox). Their accuracy is not guaranteed. The App may link to third-party websites (for example, a restaurant’s website). We are not responsible for the privacy practices of those third parties; review their policies separately.

8. International data transfers

We are based in Hong Kong, and our providers may process data in various countries. Where we transfer personal data internationally (including from the EEA/UK), we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by our providers. By using the App, you understand your data may be processed outside your country of residence.

9. Children

The App is not directed to children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact manager@echelon-app.com and we will delete it. Where local law sets a different minimum age for consent, that age applies.

10. Data retention

  • Account data and user content are retained while your account is active.
  • When you delete your account (Profile → Delete account), we delete your account, reviews, review photos, favorites, reports you filed, your avatar, and your authentication record. This removal is processed across our database and file storage.
  • We may retain limited technical logs for a short period for security and legal compliance, after which they are deleted or anonymized.

11. Your privacy rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data («right to be forgotten») — available directly in the App via Profile → Delete account;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent at any time (this does not affect prior lawful processing);
  • lodge a complaint with your local data protection authority.

To exercise any right, email manager@echelon-app.com. We will respond within the timeframe required by applicable law.

12. Region-specific disclosures

  • Hong Kong (PDPO). We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486). You may request access to and correction of your personal data, and ask about our data-handling policies, via the contact above.
  • EEA / United Kingdom (GDPR / UK GDPR). See Sections 5 and 11. You may contact your local supervisory authority.
  • Thailand (PDPA). As the App primarily serves users in Thailand, where the Personal Data Protection Act applies we honor the corresponding rights of access, correction, deletion, and objection described in Section 11.
  • California (CCPA/CPRA). We do not sell or «share» personal information for cross-context behavioral advertising. California residents may request access and deletion as described above.

13. Security

We use industry-standard measures to protect your data, including encrypted transport (HTTPS/TLS), authentication, and access controls on our backend. Uploaded review photos are stored in our file storage and may be publicly accessible by design (reviews are public). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

14. Changes to this Policy

We may update this Privacy Policy from time to time. The «Last updated» date at the top reflects the latest version. Material changes will be communicated in the App or on our website. Continued use of the App after changes take effect constitutes acceptance.

15. Contact us

Echelon Apps Limited
Email: manager@echelon-app.com
Website: https://echelon-app.com/


This document is published at https://echelon-app.com/ and referenced from within the Tom Yum app and its App Store listing.