/ EN
Sign up free
Home Features Catalog Blog Use Cases Our Story

Privacy Policy

How OMIPOKA collects, uses, and protects your personal data, and the rights you have under GDPR and Taiwan's PDPA.

Last updated: 2026-09-07

1. Information We Collect

When you use OMIPOKA (the “Service”), we collect the following to power account features and NFC card functionality:

  • Account data: email, display name, optional avatar
  • Card content: data you create on cards (names, contact info, video links, etc.)
  • Photos and video assets: photos you upload to a card (Guardian-card portrait, business-card avatar, etc.); the 3–8 photos and captions of a Video Gift Card “Photo Story”, and the mp4 video rendered from those photos
  • Device info: FCM push token, browser + OS identifier strings
  • Usage records: card tap events, view count, share count

2. How We Use Your Information

  • To provide account auth + card creation, editing, publishing
  • To push you a notification when your card is tapped (if you have enabled notifications)
  • For product improvement + feature design (aggregated, de-identified analysis only)
  • For legal compliance and account security

3. Third Parties

The Service uses the following third-party platforms:

  • Google Firebase: account auth, Firestore database, FCM push, Cloud Functions (Photo Story video rendering: your photos are cut into a video server-side with FFmpeg; no face recognition or content analysis) (subject to Google Cloud terms)
  • Cloudflare: page hosting, R2 image and video storage (card photos, Photo Story assets and exported mp4 files), KV allowlists (subject to Cloudflare terms)
  • ECPay: payment processing (credit card, ATM transfer, convenience-store codes); the Service never stores your full card number
  • PayPal (PayPal Pte. Ltd.): payment, refund and dispute processing for orders paid with PayPal; the Service only receives the payment status, transaction IDs and the payer’s country, never card numbers
  • LINE (LY Corporation): guardian-card notifications and customer-service chat
  • Resend: transactional and notification email delivery
  • SuiteDash: customer relationship management (CRM), support-ticket handling and news & updates delivery. Every member’s email, name, interface language, plan (free / pro), purchase status and de-identified card-interest category are synced as a CRM contact record so support can identify and reply to you; only members who actively subscribe are added to the mailing list (see Section 10)
  • Google Analytics 4 (loaded via Google Tag Manager): anonymous traffic and conversion analytics, enabled only after you accept analytics cookies (see the Cookie Policy)
  • Anthropic: AI support-chat processing — messages you send to the on-site AI assistant are forwarded to Anthropic’s Claude model to generate replies. Please do not enter personal data in the AI chat

4. Your Rights (GDPR / PDPA)

You may, at any time:

  • View your personal data (Settings → “Download my data” JSON export)
  • Correct inaccuracies (edit on the Settings page)
  • Delete your account (Settings → “Delete account”, with a 30-day buffer)
  • Withdraw consent for specific uses (e.g. notifications, newsletter)

5. Data Retention

Account data: kept for the lifetime of the account. Fully purged within 30 days of deletion.

Photos and video files: kept for the lifetime of the card they belong to. Re-uploading a photo to the same slot overwrites the previous file, and the Service keeps no copy of the overwritten photo; a photo removed in the editor but not overwritten is deleted together with the card. When a card is deleted (including cards deleted as part of account deletion), its photos, Photo Story assets and exported mp4 files are automatically removed from storage, within 30 days at the latest.

Anonymous analytics: de-identified, kept up to 24 months for product improvement.

AI support-chat conversations: automatically deleted after 90 days.

6. Cookies

The Service uses cookies to maintain login state and device preferences. See the Cookie Policy for details.

7. Sensitive Personal Data (Medical, Health, Minors)

Under Taiwan’s Personal Data Protection Act Article 6, the Service may collect the following “sensitive personal data” through its Guardian card features:

  • Dementia diagnosis (Guardian / dementia mode)
  • Chronic conditions, allergies, medication lists (Guardian / medical mode)
  • Personal data of minors under 18 (Child Guardian card)

This data:

  • Is opt-in by default and not displayed on the public page
  • Requires explicit consent via a checkbox in the card editor
  • Is stored in Firebase Firestore, transmitted over TLS 1.3
  • Can be withdrawn from public display at any time via the dashboard

8. Location (GPS) Data Collection

When a visitor on a Guardian card’s public page taps the “Share location to help locate” button, the Service uses the browser’s navigator.geolocation API to capture the visitor’s current coordinates (latitude + longitude + accuracy, ±5–10 m). Uses:

  • Recorded into the tap_event log so the card owner can see “tap location” in the dashboard
  • Sent via FCM push to the card owner with a Google Maps link

Visitors must grant explicit browser geolocation permission; permission can be revoked at any time via browser settings. The Service never tracks location in the background — only on a single “share to help locate” action.

9. Third-Party Personal Data Notice (Family Contacts)

Family contact information (name, phone, relationship, email) provided when building a Guardian card is stored and displayed per the user’s instructions. Users must obtain informed consent from that third party under Section 10 of the Terms of Service (Third-Party Personal Data & User Responsibility).

The same applies to photos you upload to a card (including a Video Gift Card “Photo Story”) that show other people: obtain their consent first. The Service stores and displays those photos only as you direct and does not use them for any other purpose.

OMIPOKA reserves the right to take down the relevant card’s public page without the user’s consent upon receipt of a third-party objection.

9-1. Emergency Contact Email Alerts

When either of the following two events occurs on a Guardian card, the Service sends an alert email via Resend (Delaware, USA — a GDPR-compliant transactional email provider) to the emergency contact email addresses the card owner entered in the card editor:

  • Location shared (share-location): a finder on the public page actively grants browser geolocation permission and taps “I’m willing to share my location”.
  • Sensitive information viewed (sensitive-view): a finder on the public page actively expands sensitive fields such as medical information, allergies, or medications.

Ordinary card opens (tap-opened) do not trigger emails to family contacts — only the card owner receives push and email — to avoid flooding family inboxes with high-frequency events.

Legal basis for processing:

  • Taiwan Personal Data Protection Act Article 19, Paragraph 1, Subparagraph 5: “with the data subject’s consent” — the card owner warrants at card creation that they have obtained the family contact’s consent to provide their email (see Section 10 of the Terms of Service).
  • Purpose of collection: sending the two kinds of recovery and safety alert transactional emails described above.
  • Scope of collection: the family contact’s name, email, relationship (free text entered by the card owner), and send timestamps.
  • Retention: for the lifetime of the Guardian card; deleted when the card owner deletes the card or their account.

Anti-spam mechanisms:

  • Per family recipient × per card × per event type, at most 1 email per minute (absorbs double-taps / browser retries; Firestore TTL dedupe collection).
  • Alert emails contain no ads, marketing, or tracking pixels — only event details and the necessary CTA.

Family-side rights:

  • Every alert email includes a personalised unsubscribe link in the footer (HMAC-signed against forgery); family contacts can self-unsubscribe at any time.
  • After unsubscribing, the Service marks receiveAlerts: false and unsubscribedAt in Firestore, and that contact will no longer receive any alert emails for that card.
  • Unsubscribing does not affect the card owner’s ability to reach the contact by phone (phone numbers are displayed on the card’s public page).
  • To resume receiving alerts, ask the card owner to re-invite you from the dashboard.

Family contacts with questions about the Service’s data handling may contact us via the Service’s support channels (Help Center); we will respond within 30 days.

10. Email Marketing & Newsletter

The Service’s email communication follows a dual-track architecture:

I. Transactional Email (Orders & System Notifications)

Sent via Resend (Delaware, USA, GDPR-compliant). Uses include:

  • Order confirmation, payment details, shipping updates, burn-in complete, transfer code, refund status
  • Account verification, password reset
  • Security alerts (NFC tampering / unusual access detection)

These messages are required to deliver the Service and are not governed by the newsletter opt-in toggle.

II. News & Updates (Newsletter)

Sent via SuiteDash (Delaware, USA, GDPR-compliant) and delivered through Resend. Requires your active consent (default off): tick the box on the sign-up page, the checkout page or the website subscribe page, or turn it on in Settings. Content includes:

  • Product updates and new feature introductions
  • Promotions and seasonal campaigns
  • Guardian card use-case stories
  • User stories and community sharing

Subscriber data handling:

  • The Service syncs your email, name, interface language, plan (free / pro), purchase status and a de-identified card-interest category (never the specific card type or any health-related category) to SuiteDash
  • Non-subscribers also have a CRM contact record (see Section 3) but are never added to the mailing list
  • Your personal data is never provided to any third party for marketing
  • You can unsubscribe at any time via Settings or the email footer link
  • On unsubscribe we stop sending and remove you from the list; on account deletion we also clear the synced fields and flag the record for deletion, which the Service purges periodically
  • SuiteDash collects your open / click behaviour to improve content quality

III. Bounce Handling

If your email bounces for system reasons, the Service flags and pauses sending automatically to protect your email reputation. Please update your email in Settings.

IV. Dual-Platform GDPR Compliance

The Service’s email system uses Resend (transactional) and SuiteDash (news & updates), both Delaware, USA registered providers meeting the following compliance requirements:

  1. EU-U.S. Data Privacy Framework (DPF) certification — Both providers are listed on the U.S. Department of Commerce DPF registry, satisfying the EU GDPR Article 45 “adequacy decision” requirement.
  2. Data Processing Agreement (DPA) — The Service has signed DPAs with both Resend and SuiteDash, defining the controller–processor relationship per GDPR Article 28, including data retention, deletion request forwarding, and sub-processor notification.
  3. Storage & transmission — Transactional content is not retained long-term after delivery; only essential audit metadata (send time, recipient hash, deliverability status) is kept ≤ 90 days. Mailing-list membership and behaviour tracking (open, click) are retained by SuiteDash; on unsubscription you are removed from the list, and on account deletion the synced fields are cleared and the record flagged for periodic purge. Transmission uses TLS 1.2+; data at rest is AES-256 encrypted.
  4. Single point of contact for your rights — Under GDPR Articles 15–22, you may exercise rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making over data on both platforms by contacting OMIPOKA ([email protected]). The Service completes handling (including forwarding to Resend / SuiteDash) within 30 days.
  5. Cross-border transfer notice — Your email data will be transferred to the United States for processing. If you do not consent to this cross-border transfer, do not subscribe to the newsletter; transactional email is required to deliver the Service and cannot be opted out of.

11. Contact Us

For privacy questions or to exercise the rights above, email [email protected].

One more layer of protection for those who matter

Sign up free and get 3 cards — guardian, video gift, business cards and more.

Start free