CutiVerse Privacy Policy

Updated:

This policy applies to the CutiVerse website and its Discord bots. It explains how we handle your personal data when providing membership, event tickets, refunds, customer support and related services.

Contents

1. Scope and contact

Operator and data controller
可愛神殿有限公司
Privacy contact email
cutiverseco@gmail.com
Address
No. 20-2, Sec. 1, Kaifeng St., Zhongzheng Dist., Taipei City, Taiwan

External recruitment forms, employee personnel management and services independently provided by third parties are subject to their applicable personal data notices or privacy policies.

2. Data we collect and why

Depending on the features you use, we obtain data you provide, data generated through service use, or data provided with your authorization by third parties such as Discord and payment services:

Account and membership
Username, member identifier, password hash, birthday, mobile number, email, verification and terms acceptance records, membership level, points and coupon records. These support sign-in, verification, membership benefits and abuse prevention.
Events and transactions
Orders, events, sessions, ticket types, performer nominations, passes, redemption and gift records, amounts, payment methods, payment and refund statuses, and invoice details including necessary contact information, invoice carriers, invoice titles and business tax IDs. These support transactions, on-site services, reconciliation and tax matters.
Refunds and support
Request and processing records, and text and images you provide. Bank-transfer refunds also require the recipient name, bank, branch and account, for refund and case processing.
Discord
Account ID, username, display name, avatar identifiers, authorized email, linking records, and relevant server membership, role and notification statuses. See section 4 for their purposes.
Website and security
IP address and approximate inferred region, device and browser information, cookies, sign-in and activity records, for security verification, service operation, troubleshooting and website analytics.

Online card details are handled by the payment provider's payment component. We process orders using transaction identifiers and payment results. Do not include passwords, verification codes, card security codes or unrelated third-party information in support messages or images.

You do not need to sign in to browse public information. Without data required for registration, transactions or bank refunds, the corresponding service may be unavailable. Support text, images and Discord linking are optional and are not required for every purchase or refund. See section 5 for how cookie choices affect website features.

3. Use and sharing

We use data only as necessary to provide services, fulfill transactions, resolve disputes, maintain security and meet legal obligations. We do not sell your personal data. Data may be shared with:

  • The operating companies responsible for the service and authorized staff, according to their duties in membership, on-site service, support and finance.
  • 91APP Payments, relevant financial institutions and the e-invoice provider 易發票, for payments, refunds, reconciliation and invoicing.
  • Security and storage providers such as Cloudflare, and hosting, database, backup, email, SMS and maintenance providers.
  • Discord, Google Analytics and Microsoft Clarity, for notifications, account services and website analytics respectively.
  • Authorities legally entitled to request data, or professionals assisting with disputes to the extent necessary.

Data is stored, matched, queried and transmitted electronically, automatically and, when necessary, manually. Our website server is in Japan. Our MongoDB database is in Google Cloud's Taiwan region (asia-east1). We are still verifying the processing regions of other cloud, backup and third-party services and will update this policy after confirmation. These services may involve cross-border transfers, which we handle in accordance with applicable law.

For new uses outside the purposes originally disclosed, we will provide further notice or obtain necessary consent as required by law.

4. Discord services

After you link Discord, we use the data listed in section 2 to connect your membership account, verify relevant server membership, synchronize roles and send service notifications. Our bots do not currently read general channel conversations or users' direct messages. Discord API data is not sold or used for unrelated personal profiling or training AI models.

To handle website refunds and support, we send necessary usernames, orders, events, sessions, ticket names, amounts, payment methods, and support text and images to work-related Discord channels, where copies remain. Separate bank recipient forms are not automatically included in notifications, but data you put in text or images may be forwarded with the message. Discord handles data under its own Privacy Policy.

You can unlink Discord on the website to remove the current linked data and stop synchronization and notifications based on that link. Contact us if role removal fails. Unlinking does not delete orders, support records or messages already sent, and does not stop website support notifications unrelated to linking. You may request deletion under section 7; retention principles are in section 6.

5. Cookies and analytics

We use essential cookies or similar technologies for sign-in, security verification and service processes. Blocking them may affect related features.

Some pages use Google Analytics and Microsoft Clarity to analyze page views, device and browser information, clicks, scrolling and session replay to improve services. Analytics starts only after your consent, not before you choose or if you decline. Acceptance of membership terms does not replace this analytics choice.

You can change your choice in Cookie settings. It is stored in this browser for 180 days. Under the current website settings, declining pauses general website features, but you can still read this policy and the membership terms, get help with existing orders and refunds, or contact us. Changing your choice does not automatically delete data already sent.

6. Retention and security

We currently have no fixed automatic deletion period for accounts and memberships, orders, refunds, invoices, support conversations, images, bank refund details or work-related Discord notification copies. They are not automatically deleted solely because of prolonged inactivity, a completed transaction or a closed case. We retain data to the extent and for the period necessary for services, reconciliation, taxes, legal obligations and dispute resolution:

Account and membership
Retained as necessary to provide account and membership services. Accounts are not automatically deleted for prolonged inactivity. Membership levels, points and ticket records in an account have no fixed automatic deletion period. Deleting the main account record also removes membership data held in it. Separately stored transaction, refund and discount coupon records are not automatically deleted with it; they are handled according to their purposes and this section.
Discord linking
Retained while linked. Unlinking removes associated data from the current member record. Other records follow their respective categories.
Orders, refunds and invoices
Retained for the period necessary for transactions, accounting, taxes and disputes. They are not automatically deleted when an order or refund is completed.
Support, images, bank refund details and Discord notification copies
Retained for the period necessary for case handling, refund verification and related disputes. They are not automatically deleted when a case closes.

The absence of an automatic deletion period does not mean all data may be retained indefinitely without conditions, nor does it affect your rights under section 7. When the purpose no longer applies or the retention period ends, we will delete or de-identify data, or stop processing and using it as required by law. Data still needed by law or for unresolved disputes is limited to the necessary scope and use. Backup data is included in deletion request assessments; deleting an account does not mean all backup copies are immediately removed.

We use access controls, password hashing, encryption of bank refund details, private image access and upload restrictions, but cannot guarantee zero risk. If a data security incident occurs, we will investigate, limit its impact and provide legally required notifications.

7. Your rights and deletion

As provided by law, you may request to inquire about, view, obtain copies of, supplement or correct your personal data, or request that its collection, processing and use stop, or that it be deleted.

Email cutiverseco@gmail.com with the subject "CutiVerse 個資申請" (CutiVerse personal data request). Describe your request and provide your member username or Discord user ID for verification. For transactions or support, you may provide an order or case number. We will perform necessary identity checks and respond within the applicable statutory period. We will explain any lawful retention, inability to process the request or extension.

Deletion requests assess membership data, attachments, Discord message copies under our control and backups, not only unlinking. Data independently retained by third parties such as Discord requires a separate request to that provider.

8. Policy updates

Updates are dated. Significant changes to data purposes, recipients or rights will be announced on the website or by another appropriate method, with consent obtained where required by law. For questions, contact us using the details in section 1.