/ EN
Sign up free
Home Features Catalog Blog Use Cases Our Story

Privacy Policy

How OMIPOKA collects, uses, and protects your personal data, and the rights you have under GDPR and Taiwan's PDPA.

Last updated: 2026-07-08

1. Information We Collect

When you use OMIPOKA (the “Service”), we collect the following to power account features and NFC card functionality:

  • Account data: email, display name, optional avatar
  • Card content: data you create on cards (names, contact info, video links, etc.)
  • Device info: FCM push token, browser + OS identifier strings
  • Usage records: card tap events, view count, share count

2. How We Use Your Information

  • To provide account auth + card creation, editing, publishing
  • To push you a notification when your card is tapped (if you have enabled notifications)
  • For product improvement + feature design (aggregated, de-identified analysis only)
  • For legal compliance and account security

3. Third Parties

The Service uses the following third-party platforms:

  • Google Firebase: account auth, Firestore database, FCM push (subject to Google Cloud terms)
  • Cloudflare: page hosting, R2 image storage, KV allowlists (subject to Cloudflare terms)
  • ECPay: payment processing (credit card, ATM transfer, convenience-store codes); the Service never stores your full card number
  • LINE (LY Corporation): guardian-card notifications and customer-service chat
  • Resend: transactional and notification email delivery
  • Google Analytics 4 (loaded via Google Tag Manager): anonymous traffic and conversion analytics, enabled only after you accept analytics cookies (see the Cookie Policy)
  • Anthropic: AI support-chat processing — messages you send to the on-site AI assistant are forwarded to Anthropic’s Claude model to generate replies. Please do not enter personal data in the AI chat

4. Your Rights (GDPR / PDPA)

You may, at any time:

  • View your personal data (Settings → “Download my data” JSON export)
  • Correct inaccuracies (edit on the Settings page)
  • Delete your account (Settings → “Delete account”, with a 30-day buffer)
  • Withdraw consent for specific uses (e.g. notifications, newsletter)

5. Data Retention

Account data: kept for the lifetime of the account. Fully purged within 30 days of deletion.

Anonymous analytics: de-identified, kept up to 24 months for product improvement.

  • AI support-chat conversations: automatically deleted after 90 days

6. Cookies

The Service uses cookies to maintain login state and device preferences. See the Cookie Policy for details.

7. Sensitive Personal Data (medical, health, minors)

Under Taiwan’s Personal Data Protection Act Article 6, the Service may collect the following “sensitive personal data” through its Guardian card features:

  • Dementia diagnosis (Guardian / dementia mode)
  • Chronic conditions, allergies, medication lists (Guardian / medical mode)
  • Personal data of minors under 18 (Child Guardian card)

This data:

  • Is opt-in by default and not displayed on the public page
  • Requires explicit consent via a checkbox in the card editor
  • Is stored in Firebase Firestore, transmitted over TLS 1.3
  • Can be withdrawn from public display at any time via the dashboard

8. Location (GPS) Data Collection

When a visitor on a Guardian card’s public page taps the “Share location to help locate” button, the Service uses the browser’s navigator.geolocation API to capture the visitor’s current coordinates (latitude + longitude + accuracy, ±5–10 m). Uses:

  • Recorded into the tap_event log so the card owner can see “tap location” in the dashboard
  • Sent via FCM push to the card owner with a Google Maps link

Visitors must grant explicit browser geolocation permission; permission can be revoked at any time via browser settings. The Service never tracks location in the background — only on a single “share to help locate” action.

9. Third-Party Personal Data Notice (family contacts)

Family contact information (name, phone, relationship) provided when building a Guardian card is stored and displayed per the user’s instructions. Users must obtain informed consent from that third party under Section 10 of the Terms of Service (Third-Party Personal Data & User Responsibility).

OMIPOKA reserves the right to take down the relevant card’s public page without the user’s consent upon receipt of a third-party objection.

9-1. Emergency Contact Email Alerts

When the following 2 events occur on a Guardian card, the Service sends a notification email to the emergency contacts entered on the card editor, via Resend (Delaware, USA — a GDPR-compliant transactional email provider):

  • share-location: a finder on the public page actively grants browser location permission and taps “Share my location”.
  • sensitive-view: a finder on the public page actively expands sensitive fields such as medical info, allergies, or medication.

A plain card open (tap-opened) does not email the family — only the owner receives the push and email. This prevents high-frequency events from flooding family inboxes.

Legal basis for data processing:

  • Taiwan PDPA Article 19 §1 (5): “with the data subject’s consent” — the card owner warrants, at card creation, that they have obtained each family contact’s consent to provide their email (see Terms of Service §10).
  • Purpose of collection: to send the 2 transactional alert categories above.
  • Scope: family contact name, email, relationship (free text entered by the owner), send timestamp.
  • Retention: same lifetime as the Guardian card; purged when the owner deletes the card or their account.

Anti-spam mechanism:

  • Per (recipient × card × event type), at most one email per minute (absorbs double-clicks / browser retries via a Firestore TTL dedupe collection).
  • Alert emails contain no ads, marketing, or tracking pixels — only event details and necessary CTAs.

Family member rights:

  • Every alert email includes a personalised unsubscribe link (HMAC-signed to prevent forgery); family members can unsubscribe themselves at any time.
  • On unsubscribe, the Service marks receiveAlerts: false and unsubscribedAt in Firestore; that family member will no longer receive any alerts for that card.
  • Unsubscribing does not affect the owner’s ability to phone the contact (the phone number is on the public card page).
  • To re-subscribe, ask the owner to re-invite from the dashboard.

If family members have questions about how the Service handles their personal data, they may contact the Service via the help center; the Service will respond within 30 days.

10. Email Marketing & Newsletter

The Service’s email communication follows a dual-track architecture:

I. Transactional Email (orders & system notifications)

Sent via Resend (Delaware, USA, GDPR-compliant). Uses include:

  • Order confirmation, shipping updates, burn-in complete, transfer code
  • Account verification, password reset
  • Security alerts (NFC tampering / unusual access detection)

These messages are required to deliver the Service and are not governed by the newsletter opt-in toggle.

II. Newsletter (marketing)

Sent via Beehiiv (Delaware, USA, GDPR-compliant). Users must actively opt in on the Settings page (default off). Content includes:

  • Product updates and new feature introductions
  • Promotions and seasonal campaigns
  • Guardian card use-case stories
  • User stories and community sharing

Subscriber data handling:

  • The Service only syncs email, name, locale, tier, and card-type holdings to Beehiiv
  • Your personal data is never provided to any third party for marketing
  • You can unsubscribe at any time via Settings or the email footer link
  • Within 24 hours of unsubscribing, the Service automatically purges your subscription record from Beehiiv
  • Beehiiv collects your open / click behaviour to improve content quality

III. Bounce handling

If your email bounces for system reasons, the Service flags and pauses sending automatically to protect your email reputation. Please update your email in Settings.

IV. Dual-platform GDPR compliance

The Service’s email system uses Resend (transactional) and Beehiiv (newsletter), both Delaware, USA registered providers meeting the following compliance requirements:

  1. EU-U.S. Data Privacy Framework (DPF) certification — Both providers are listed on the U.S. Department of Commerce DPF registry, satisfying the EU GDPR Article 45 “adequacy decision” requirement.
  2. Data Processing Agreement (DPA) — The Service has signed DPAs with both Resend and Beehiiv, defining the controller–processor relationship per GDPR Article 28, including data retention, deletion request forwarding, and sub-processor notification.
  3. Storage & transmission — Transactional content is not retained long-term after delivery; only essential audit metadata (send time, recipient hash, deliverability status) is kept ≤ 90 days. Newsletter subscription lists and behaviour tracking (open, click) are retained by Beehiiv; on unsubscription the Service auto-purges your Beehiiv record within 24 hours. Transmission uses TLS 1.2+; data at rest is AES-256 encrypted.
  4. Single point of contact for your rights — Under GDPR Articles 15–22, you may exercise rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making over data on both platforms by contacting OMIPOKA (support@omipoka.com). The Service completes handling (including forwarding to Resend / Beehiiv) within 30 days.
  5. Cross-border transfer notice — Your email data will be transferred to the United States for processing. If you do not consent to this cross-border transfer, do not subscribe to the newsletter; transactional email is required to deliver the Service and cannot be opted out of.

11. Contact Us

For privacy questions or to exercise the rights above, email support@omipoka.com.

⚠️ This policy is a DRAFT — not to be treated as final until reviewed by counsel.

One more layer of protection for those who matter

Sign up free and get 3 cards — guardian, video gift, business cards and more.

Start free