← Back to site
Legal

Privacy Policy

Last updated: 22 July 2026

Instly Co., Ltd. — registered in Thailand, company registration no. 0105567135903 (incorporated 3 July 2024).
Registered office: Sethiwan Tower, 139 Soi Pan, Silom, Sathorn, Bangkok 10500, Thailand.
InstlyWalletPass is a product of Instly Co., Ltd. Privacy contact: privacy@instlytechnologies.com.

This policy explains how Instly Co., Ltd. ("Instly", "we", "us") handles personal data in connection with InstlyWalletPass — our platform for issuing Apple Wallet and Google Wallet passes.

1. Two different roles

Our responsibilities depend on whose data is involved:

2. Data we collect as a controller

3. Pass data we process for clients

When a client issues cards, they send us the field values that appear on each pass. We use this data solely to generate, deliver, update and revoke the wallet passes the client asks us to, and to maintain an audit record of those actions. We do not use pass-holder data for our own marketing and do not sell it. Clients are responsible for having a lawful basis to provide this data and for informing their own customers.

4. Why we use data, and our legal bases

5. Sub-processors and sharing

We use carefully selected service providers to run InstlyWalletPass, including:

We share personal data with these providers only as needed to run the service, and we may disclose data where required by law. We do not sell personal data.

6. International transfers

Instly is established in Thailand and our infrastructure is hosted in the United States, so personal data may be transferred and processed outside your country. Where required, we rely on appropriate safeguards for such transfers.

7. Retention

We keep account and billing data for as long as an account is active and as required by law afterwards. Pass and event data is retained under the arrangement we have with each client controller, and is deleted or returned on the client's instruction. Any demo cards created from our website are short-lived and deleted automatically.

8. Security

We protect data with encryption in transit, access controls, and dedicated secret storage for signing credentials. Wallet passes are cryptographically signed. No system is perfectly secure, but we work to protect data in line with good industry practice.

9. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to certain processing, or ask us to restrict it. To exercise these rights over data we control, contact privacy@instlytechnologies.com. If your request concerns a wallet card issued to you by a business, please contact that business as the controller; we will support them in responding.

10. Children

InstlyWalletPass is a business tool and is not directed at children, and we do not knowingly collect children's data through our own services.

11. Changes

We may update this policy from time to time. We will post the new version here and update the date above; material changes affecting account holders will be notified.

12. Contact

Questions or complaints: privacy@instlytechnologies.com, or write to us at the registered office above.