Privacy Policy
Last updated: 11 July 2026
Privacy Policy
Last updated: 28 June 2026
This Privacy Policy explains how Red Friend Co., Ltd., trading as Movialy (" Movialy", " we", " us", " our"), collects, uses, discloses, and protects personal data in connection with the Movialy platform, accessible at movialy.com and movialy.app (the " Service").
We are committed to protecting personal data in accordance with applicable law, including Thailand's Personal Data Protection Act (PDPA), the EU/UK General Data Protection Regulation (GDPR) where applicable, and other relevant data-protection laws.
1. Our Two Roles: Controller and Processor
Movialy plays two distinct roles depending on the data concerned:
(a) As a data controller — for personal data about our own customers and their representatives. This includes the rental-business owners, managers, and staff who create and use a Movialy Account, and the people who contact us. We decide how and why this data is processed, and this Privacy Policy governs it.
(b) As a data processor — for personal data that our customers enter into the Service about their own clients (the renters), such as names, contact details, and identity documents. For this data, our customer is the data controller and is responsible for the legal basis and notices; we process it only on the customer's documented instructions, under the Data Processing Addendum. If you are a renter and have questions about your data, please contact the rental business you dealt with — they are the controller of your data.
This Privacy Policy primarily describes our processing as a controller. Our processing as a processor is governed by the Data Processing Addendum.
2. Personal Data We Collect (as Controller)
2.1 Account and identity data
When you register or are invited as an Authorized User, we collect: company name, name of the responsible person, the names of Authorized Users, email address, telephone number, postal address, country, role, and login credentials (passwords are stored in hashed form by our authentication provider).
2.2 Billing and transaction data
When you subscribe to a paid plan, we and our payment processors collect billing information and records of transactions. We do not store full payment card numbers; card data is handled directly by our payment processors (Omise/Opn and Paddle).
2.3 Usage and technical data
We collect technical information such as IP address, device and browser type, log data, and information about how you interact with the Service, for security, troubleshooting, and improvement purposes.
2.4 Support data
When you contact support or submit a Help, Suggestion, or Bug Report, we collect the content of your message and related context (such as your company code and the relevant booking number). Bug reports may create a ticket in ClickUp.
2.5 Preferences
We store interface preferences (such as language and filters) locally in your browser. See our Cookie Policy.
3. How and Why We Use Personal Data (as Controller)
| Purpose | Legal basis (GDPR) | |---|---| | To create and administer your Account and provide the Service | Performance of a contract | | To process subscriptions, payments, and renewals | Performance of a contract | | To provide customer support and respond to requests | Performance of a contract / legitimate interests | | To secure the Service, prevent fraud and abuse, and maintain audit logs | Legitimate interests / legal obligation | | To improve and develop the Service | Legitimate interests | | To send service-related communications (e.g. changes, security notices) | Performance of a contract / legitimate interests | | To comply with legal, tax, and accounting obligations | Legal obligation | | To send marketing communications (where applicable) | Consent / legitimate interests |
Under the Thai PDPA, our processing relies on the corresponding bases, including contractual necessity, legitimate interest, legal obligation, and, where required, consent.
4. Artificial Intelligence Processing
The Service includes optional AI-assisted features (OCR of vehicle dashboards, vehicle suggestions, document classification, thumbnail generation, and automated label translation), powered in part by the Lovable AI Gateway. Where a customer enables intelligent photo scanning, certain images (such as dashboard photos) may be retained to improve model accuracy. These features can be disabled in settings. AI outputs are provided as an aid and should always be reviewed by the user.
5. Sub-Processors and Third Parties We Share Data With
We use trusted third-party service providers ("sub-processors") to operate the Service. We share personal data with them only as necessary to provide the Service and under appropriate contractual safeguards. Current sub-processors include:
| Provider | Purpose | Location (approx.) | |---|---|---| | Supabase, Inc. (via Lovable Cloud) | Database hosting, authentication, object storage, server functions | United States / EU (per project configuration) | | Cloudflare, Inc. | CDN, edge workers, PWA delivery, caching | United States; global edge network | | Lovable AI Gateway | OCR, vehicle suggestions, document classification, label translation, thumbnails | United States / EU | | ClickUp | Support tickets and bug reports | United States | | Omise / Opn Payments | Payment processing (local) | Thailand / Singapore | | Paddle | Payment processing (international) | United Kingdom / EU | | Third-party GPS tracking services (feature under development) | Optional GPS tracking connection; credentials provided by you, not stored by default | Feature under development | | Nager.Date | Automatic public-holiday data by country | European Union | | FlagCDN | Flag icons for the language selector | Global CDN |
We may also disclose personal data where required by law, to enforce our Terms, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honour this Policy).
An up-to-date list of sub-processors is maintained in this Privacy Policy (Section 5 above). We will notify customers of material changes to sub-processors as described in the Data Processing Addendum.
6. International Data Transfers
The Service relies on infrastructure that may be located in countries other than your own. Where personal data is transferred internationally, we put in place appropriate safeguards required by applicable law (such as Standard Contractual Clauses under the GDPR, or the consent/adequacy mechanisms recognized under the Thai PDPA). Details are available on request.
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy:
- Account data: for the duration of the Account, plus ninety (90) days after termination, after which it is deleted or anonymized, unless a longer period is required by law.
- Billing and transaction records: for at least five (5) years, and up to seven (7) years where required by Thai tax and accounting law.
- Support data: for twenty-four (24) months.
- Demonstration-environment data: deleted automatically on a daily reset.
- AI training images (where enabled): retained until the feature is disabled or the underlying data is deleted, whichever is earlier, then deleted.
When retention is no longer required, we delete or anonymize the data.
8. Security
We implement technical and organizational measures appropriate to the risk, including:
- Encryption in transit via HTTPS/TLS.
- Tenant isolation by
company_idenforced through Row Level Security (RLS) at the database level. - Role-based access control (RBAC) combining roles and per-feature permissions, re-verified server-side for sensitive actions.
- Signed, time-limited URLs for access to stored photos and documents.
- Change logging for bookings, clients, vehicles, and financial records.
- Restricted privileged access: a small number of super-administrator accounts may switch between companies solely for support, maintenance, and billing; such access is logged.
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
9. Your Rights
Subject to applicable law (GDPR, PDPA, and others), you may have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability (receive your data in a structured, machine-readable format);
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a supervisory authority (in Thailand, the Personal Data Protection Committee; in the EU/UK, your local data-protection authority).
To exercise these rights, contact us at
. We will respond within the timeframe required by applicable law. If your request concerns Renter Data for which a rental business is the controller, we will refer you to that business.
10. Cookies and Local Storage
The Service uses browser localStorage and sessionStorage to store user preferences (such as language and filters) and your authentication session. We do not use third-party analytics or advertising cookies by default. See our Cookie Policy for details.
11. Children
The Service is intended for business use and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, where changes are material, notify you through the Service or by email.
13. Contact
Data controller: Red Friend Co., Ltd. (trading as Movialy)
Address:
Privacy contact:
Support: In-app support, available on every page of the Movialy application