Privacy Policy

Papan
Effective date: August 10, 2026
Last updated: August 10, 2026

This Privacy Policy explains how the Papan Android application (the "App") handles device and authentication information when the App is used to operate a digital signage device.

Summary: The App collects and processes only the Android device identifier and authentication token required to authenticate a signage device and deliver authorized signage content.

1. Information We Collect

The App collects and processes the following information:

The App does not require users to provide their name, email address, telephone number, contacts, payment information, precise location, microphone recordings, or other personal profile information for the operation of the Papan service.

2. Storage and Media Access

The App requests Android storage and media permissions where required by the Android version and device configuration to download, store, access, cache, and display signage images and videos on the device.

Downloaded signage media is stored locally on the device so that the App can continue displaying authorized content when the device has limited or no network connectivity. Local storage and caching are part of the core functionality of the Papan service.

The App uses storage and media access for signage content. It does not intentionally collect, upload, analyze, or use the user's personal photos or videos for unrelated purposes.

3. How We Use Information

The Android device identifier and authentication token are used only for purposes necessary to operate the Papan service, including:

We do not use the device identifier or authentication token for advertising, behavioral profiling, or unrelated marketing purposes.

4. How Authentication Works

A signage administrator generates a unique authentication token and associates it with a shop. The token is initially stored in the backend without a device identifier.

When a device uses the token to log in, the App retrieves the Android device identifier and sends the token and device identifier to the backend. After successful authentication, the backend associates the device identifier with the token.

The resulting device and token association is used to authenticate the device and determine the signage content that the device is authorized to receive.

5. Data Storage and Retention

Authentication information is stored in the backend database so that authorized devices can be recognized and authenticated. The device identifier and token association is retained while the device remains authorized to use the service.

A signage administrator may remove or disable a device and token association from the backend. When an association is removed, the device is no longer authorized to authenticate using that association.

The App may also store authentication and signage configuration information locally on the Android device. Signage images and videos may be downloaded and cached locally for continued playback when network connectivity is unavailable.

6. Sharing of Information

We do not sell, rent, or use the Android device identifier or authentication token for advertising.

The information described in this policy may be processed by the systems and infrastructure used to operate the Papan backend and signage content delivery service. Such processing is limited to providing, maintaining, securing, and operating the service.

We do not intentionally share the device identifier or authentication token with advertisers or data brokers.

7. Signage Content

After authentication, the App downloads signage content assigned to the authorized device. This content may include images, videos, and other media configured by the signage administrator.

Authorized signage content may be cached and stored locally on the device so that playback can continue during temporary network outages or other connectivity interruptions.

The App does not use downloaded signage content to create advertising profiles or behavioral profiles of users.

8. Security

Reasonable technical and organizational measures are used to protect information handled by the Papan service against unauthorized access, alteration, disclosure, or destruction.

Authentication information is transmitted between the App and the backend over network connections configured for the Papan service. Access to backend authentication records is restricted to authorized personnel and systems as appropriate for operating the service.

9. Children's Privacy

Papan is a business signage application intended for use by organizations and authorized signage operators. It is not designed to collect personal information from children.

10. Data Deletion and Access

The App does not provide consumer account registration. Access to the Papan service is controlled through an authentication token provided for use with the application.

Users cannot directly delete their device and token information from the backend through the App. If a user wants their device and associated token information removed from our backend, they may contact the service operator and request deletion.

We may verify the request before deleting the associated device and token information.

11. Changes to This Privacy Policy

This Privacy Policy may be updated when the App, backend service, or applicable privacy requirements change. When changes are made, the "Last updated" date at the top of this page will be updated.

12. Contact

For questions about this Privacy Policy or requests concerning device and token information, please contact the service operator through the contact information provided with the Papan service.