CutiVerse Privacy Policy
Updated:
This policy applies to the CutiVerse website and its Discord bots. It explains how we handle your personal data when providing membership, event tickets, refunds, customer support and related services.
Contents
1. Scope and contact
- Operator and data controller
- 可愛神殿有限公司
- Privacy contact email
- cutiverseco@gmail.com
- Address
- No. 20-2, Sec. 1, Kaifeng St., Zhongzheng Dist., Taipei City, Taiwan
External recruitment forms, employee personnel management and services independently provided by third parties are subject to their applicable personal data notices or privacy policies.
2. Data we collect and why
Depending on the features you use, we obtain data you provide, data generated through service use, or data provided with your authorization by third parties such as Discord and payment services:
- Account and membership
- Username, member identifier, password hash, birthday, mobile number, email, verification and terms acceptance records, membership level, points and coupon records. These support sign-in, verification, membership benefits and abuse prevention.
- Events and transactions
- Orders, events, sessions, ticket types, performer nominations, passes, redemption and gift records, amounts, payment methods, payment and refund statuses, and invoice details including necessary contact information, invoice carriers, invoice titles and business tax IDs. These support transactions, on-site services, reconciliation and tax matters.
- Refunds and support
- Request and processing records, and text and images you provide. Bank-transfer refunds also require the recipient name, bank, branch and account, for refund and case processing.
- Discord
- Account ID, username, display name, avatar identifiers, authorized email, linking records, and relevant server membership, role and notification statuses. See section 4 for their purposes.
- Website and security
- IP address and approximate inferred region, device and browser information, cookies, sign-in and activity records, for security verification, service operation, troubleshooting and website analytics.
Online card details are handled by the payment provider's payment component. We process orders using transaction identifiers and payment results. Do not include passwords, verification codes, card security codes or unrelated third-party information in support messages or images.
You do not need to sign in to browse public information. Without data required for registration, transactions or bank refunds, the corresponding service may be unavailable. Support text, images and Discord linking are optional and are not required for every purchase or refund. See section 5 for how cookie choices affect website features.
3. Use and sharing
We use data only as necessary to provide services, fulfill transactions, resolve disputes, maintain security and meet legal obligations. We do not sell your personal data. Data may be shared with:
- The operating companies responsible for the service and authorized staff, according to their duties in membership, on-site service, support and finance.
- 91APP Payments, relevant financial institutions and the e-invoice provider 易發票, for payments, refunds, reconciliation and invoicing.
- Security and storage providers such as Cloudflare, and hosting, database, backup, email, SMS and maintenance providers.
- Discord, Google Analytics and Microsoft Clarity, for notifications, account services and website analytics respectively.
- Authorities legally entitled to request data, or professionals assisting with disputes to the extent necessary.
Data is stored, matched, queried and transmitted electronically, automatically and, when necessary, manually. Our website server is in Japan. Our MongoDB database is in Google Cloud's Taiwan region (asia-east1). We are still verifying the processing regions of other cloud, backup and third-party services and will update this policy after confirmation. These services may involve cross-border transfers, which we handle in accordance with applicable law.
For new uses outside the purposes originally disclosed, we will provide further notice or obtain necessary consent as required by law.
4. Discord services
After you link Discord, we use the data listed in section 2 to connect your membership account, verify relevant server membership, synchronize roles and send service notifications. Our bots do not currently read general channel conversations or users' direct messages. Discord API data is not sold or used for unrelated personal profiling or training AI models.
To handle website refunds and support, we send necessary usernames, orders, events, sessions, ticket names, amounts, payment methods, and support text and images to work-related Discord channels, where copies remain. Separate bank recipient forms are not automatically included in notifications, but data you put in text or images may be forwarded with the message. Discord handles data under its own Privacy Policy.
You can unlink Discord on the website to remove the current linked data and stop synchronization and notifications based on that link. Contact us if role removal fails. Unlinking does not delete orders, support records or messages already sent, and does not stop website support notifications unrelated to linking. You may request deletion under section 7; retention principles are in section 6.
6. Retention and security
We currently have no fixed automatic deletion period for accounts and memberships, orders, refunds, invoices, support conversations, images, bank refund details or work-related Discord notification copies. They are not automatically deleted solely because of prolonged inactivity, a completed transaction or a closed case. We retain data to the extent and for the period necessary for services, reconciliation, taxes, legal obligations and dispute resolution:
- Account and membership
- Retained as necessary to provide account and membership services. Accounts are not automatically deleted for prolonged inactivity. Membership levels, points and ticket records in an account have no fixed automatic deletion period. Deleting the main account record also removes membership data held in it. Separately stored transaction, refund and discount coupon records are not automatically deleted with it; they are handled according to their purposes and this section.
- Discord linking
- Retained while linked. Unlinking removes associated data from the current member record. Other records follow their respective categories.
- Orders, refunds and invoices
- Retained for the period necessary for transactions, accounting, taxes and disputes. They are not automatically deleted when an order or refund is completed.
- Support, images, bank refund details and Discord notification copies
- Retained for the period necessary for case handling, refund verification and related disputes. They are not automatically deleted when a case closes.
The absence of an automatic deletion period does not mean all data may be retained indefinitely without conditions, nor does it affect your rights under section 7. When the purpose no longer applies or the retention period ends, we will delete or de-identify data, or stop processing and using it as required by law. Data still needed by law or for unresolved disputes is limited to the necessary scope and use. Backup data is included in deletion request assessments; deleting an account does not mean all backup copies are immediately removed.
We use access controls, password hashing, encryption of bank refund details, private image access and upload restrictions, but cannot guarantee zero risk. If a data security incident occurs, we will investigate, limit its impact and provide legally required notifications.
7. Your rights and deletion
As provided by law, you may request to inquire about, view, obtain copies of, supplement or correct your personal data, or request that its collection, processing and use stop, or that it be deleted.
Email cutiverseco@gmail.com with the subject "CutiVerse 個資申請" (CutiVerse personal data request). Describe your request and provide your member username or Discord user ID for verification. For transactions or support, you may provide an order or case number. We will perform necessary identity checks and respond within the applicable statutory period. We will explain any lawful retention, inability to process the request or extension.
Deletion requests assess membership data, attachments, Discord message copies under our control and backups, not only unlinking. Data independently retained by third parties such as Discord requires a separate request to that provider.
8. Policy updates
Updates are dated. Significant changes to data purposes, recipients or rights will be announced on the website or by another appropriate method, with consent obtained where required by law. For questions, contact us using the details in section 1.