MonoFire Privacy Policy (Draft)
⚠️ AI-GENERATED DRAFT / NOT LEGAL ADVICE: This document was generated by AI from the product context provided. It is for internal review and lawyer editing only and is not legal advice. Before publication, production use, payment-provider onboarding, or use as an official policy, it must be reviewed and revised by qualified counsel based on MonoFire’s actual operations, data flows, payment setup, and applicable laws.
Last updated: [Date]
This Privacy Policy explains how [Company Legal Name] (Taiwan Unified Business No.: [統一編號]; Responsible Person: [負責人]; Registered Address: [登記地址]; Contact Email: [聯絡 Email]) (“Company,” “we,” “us,” or “our”) collects, processes, uses, and protects personal data through MonoFire (the “Service”).
MonoFire is an integrated creator and social-commerce SaaS toolkit, including group-buy, one-page sales page, LINE e-business-card, and Link-in-Bio products.
1. Who this policy applies to
This Policy applies to:
- Creators, merchants, team members, administrators, and other users who register for, log in to, or use MonoFire (“Users”).
- End-customers, leads, prospects, or visitors who submit data through forms, pages, campaigns, group-buy flows, or links created by Users (“End Customers”).
- Visitors to MonoFire’s website, documentation, support, or marketing pages.
If you are an End Customer, please note that the User who created the form or page often determines why and how your data is collected and used. In that context, the User may be your primary seller, service provider, or data user. We provide system tools and hosted processing services and process data under this Policy and our agreements with Users.
2. Categories of data we collect
Depending on the features used, we may collect the following data.
2.1 Account and identity data
- Name, display name, company/brand name, job title, phone number, and email address.
- Login identity data, such as Google OAuth ID, email, display name, and profile image, depending on the authorized scope.
- Magic-link email login records, login time, and verification status.
- Team membership, roles, permissions, and account status.
2.2 Authentication, session, and security data
- Login records, session cookies, token hashes, device data, IP address, browser, and operating system data generated by BetterAuth or our authentication systems.
- Security audit logs, such as failed login attempts, permission changes, suspicious activity, and password or magic-link requests.
2.3 Product content and commerce data
- Products, services, group-buy campaigns, one-page sales pages, LINE e-business cards, Link-in-Bio pages, images, text, prices, campaign rules, page settings, and public links created or uploaded by Users.
- Orders, inquiries, lead-management data, form fields, form submissions, notes, tags, and statuses.
- Support, technical assistance, and communications with us.
2.4 End Customer and lead data
- Data submitted by End Customers through User pages or forms, such as name, phone number, email, LINE ID or other social account, shipping/contact address, responses, needs, preferences, notes, and data collected through User-defined fields.
- Submission time, source page, referral source, UTM parameters, device, and browser data.
2.5 Analytics and usage data
- Page views, clicks, conversions, form submissions, link clicks, traffic sources, campaign performance, device type, approximate location, usage frequency, and feature usage logs.
- We may create aggregated or de-identified statistics to analyze and improve the Service.
2.6 LINE integration data
Depending on the LINE features enabled by Users and the authorized scope, we may process:
- LINE user ID, display name, profile image, status message, or other data provided by LINE APIs with authorization.
- LINE Login, LIFF, Messaging API, or related channel settings, tokens, webhook events, friend/interaction status, message delivery records, or event metadata.
- Data used for LINE e-business cards, lead synchronization, interaction tracking, or message triggers.
2.7 Payment, subscription, and billing data
- Plan, subscription status, payment amount, currency, invoice/receipt data, discounts, renewal date, cancellation records, refund records, failed payments, and dispute records.
- Payment transaction IDs, payment-method type, and necessary transaction data returned by payment service providers.
- We currently or may in the future process payments through NewebPay, Stripe, PayUni, or other payment services. Unless expressly stated otherwise, we do not store full card numbers; full payment credentials are processed by payment service providers under their own terms and privacy policies.
2.8 Cookies and similar technologies
We use necessary cookies, including session cookies, to maintain login state, security, and Service functionality. We may also use analytics or marketing cookies or similar technologies to understand usage and improve the Service. Where required by law, we will obtain your consent or provide an opt-out mechanism.
3. Purposes of processing
We may use data to:
- Create, verify, maintain, and secure accounts.
- Provide MonoFire features, including group-buy, one-page sales pages, LINE e-business cards, Link-in-Bio, lead capture, analytics, and related tools.
- Process subscriptions, payments, renewals, refunds, invoices/receipts, reconciliation, payment-provider review, and disputes.
- Provide support, system notices, transaction notices, security alerts, service updates, and administrative messages.
- Analyze usage, improve features, debug, test, maintain, monitor security, and prevent fraud.
- Help Users manage End Customer leads, form submissions, campaign performance, and social-commerce workflows according to User settings.
- Send product, marketing, or event communications where you have consented or where permitted by law. You may unsubscribe as described in the message.
- Perform contracts, comply with legal obligations, respond to regulators or courts, and establish, exercise, or defend legal claims.
4. Taiwan PDPA notice items and scope of use
Under Taiwan’s Personal Data Protection Act, when collecting personal data, we are required to notify data subjects of the non-government agency name, purposes of collection, categories of personal data, period/territory/recipients/methods of use, rights and exercise methods, and the impact of not providing data.
- Non-government agency: [Company Legal Name]
- Purposes: providing, managing, maintaining, improving, and marketing MonoFire; processing subscriptions, payments, support, security, compliance, and disputes.
- Period: the Service use period, account existence period, contract or transaction relationship period, legal/accounting retention period, dispute or legal-claim period, or other period necessary until the collection purpose no longer exists.
- Territory: Taiwan and locations where our cloud, payment, LINE/Google integration, communications, analytics, and other service providers operate or store data.
- Recipients: us; service providers; payment providers; communications/email providers; cloud and analytics providers; LINE, Google, and other integration providers; professional advisers; regulators; courts; and third parties designated by Users.
- Methods: automated or non-automated collection, recording, storage, editing, retrieval, transmission, analysis, de-identification, deletion, and other processing necessary for the above purposes.
If you do not provide necessary data, you may be unable to create an account, log in, use certain features, complete payments, receive notices, or obtain support.
5. Sharing and commissioned processing
We do not sell your personal data. To provide the Service, we may share or commission processing of data with:
- Cloud and infrastructure providers for hosting, backup, databases, monitoring, and security.
- Authentication and communications providers for Google OAuth, email magic links, notifications, and support systems.
- Payment providers such as NewebPay, Stripe, PayUni, or other payment services for payment, refund, reconciliation, risk control, disputes, and compliance.
- LINE and social integration services to process LINE-related data based on features and authorizations you enable.
- Analytics and product-improvement tools for service analytics, error tracking, and performance measurement.
- Professional advisers and authorities for accounting, legal, tax, audit, regulatory, or court purposes.
- User-designated recipients when Users export leads, connect third-party tools, or configure webhooks.
We require service providers to protect data by contract and applicable law within a reasonable scope.
6. Cross-border transfers
Because cloud services, payment providers, authentication, analytics, and LINE/Google integrations may operate outside Taiwan, your data may be transferred to, stored in, or processed in other jurisdictions. We will take reasonable protective measures under applicable law and, where necessary, enter into data protection or processing terms with service providers.
7. End Customer data and User responsibilities
When Users collect End Customer data through MonoFire, Users are responsible for ensuring that they:
- Have a lawful basis to collect, process, and use the data.
- Provide End Customers with required notices, privacy terms, marketing consents, and unsubscribe methods.
- Do not use custom form fields to collect data beyond what is necessary or lawful.
- Are responsible for their own products, services, campaigns, refunds, returns, warranties, support, and consumer disputes.
If an End Customer sends us a data-rights request for data controlled by a User, we may notify or refer the request to the relevant User for assistance.
8. Retention
We retain data only for as long as necessary for the purposes described above, considering contract performance, customer support, payment and accounting records, legal retention, tax, security, audit, disputes, and legal claims.
After account deletion, we may retain backups, transaction records, invoices, payment records, audit logs, and compliance records for a reasonable period. Anonymous or aggregated data may be retained without these limits.
9. Security
We use reasonable technical and organizational measures to protect data, such as access controls, encrypted transmission, permission management, audit logs, backups, security monitoring, and least-privilege principles. However, no online service can guarantee absolute security. If we become aware of theft, alteration, damage, loss, or leakage of personal data, we will take notification and remediation measures required by applicable law.
10. Your rights
Under Taiwan’s Personal Data Protection Act, you may request to:
- Inquire about or review your personal data.
- Obtain a copy of your personal data.
- Supplement or correct your personal data.
- Stop collection, processing, or use of your personal data.
- Delete your personal data.
To exercise rights, contact us at [聯絡 Email]. We may need to verify your identity and may charge necessary costs where permitted by law. We may limit or refuse a request where retention is required by law or contract, others’ rights are affected, or the data is controlled by a User, and we will explain the reason where appropriate.
11. Marketing communications
Where you consent or where permitted by law, we may send product updates, events, or marketing messages. You can unsubscribe using the link in the email or by contacting [聯絡 Email]. Even if you unsubscribe from marketing messages, we may still send billing, transaction, security, service-change, or legal notices.
12. Children and minors
The Service is primarily intended for merchants, creators, and teams with full legal capacity. Minors may use the Service only with consent from a legal representative. Users must not unlawfully collect children’s or minors’ data through the Service. If a User’s campaign collects data from children or minors, the User must obtain required consents and comply with applicable law.
13. Third-party websites and services
The Service may link to LINE, Google, NewebPay, Stripe, PayUni, or third-party websites/services configured by Users. Those third parties process data under their own terms and privacy policies. We are not responsible for third-party policies or practices.
14. Changes to this Policy
We may update this Policy due to Service, legal, or operational needs. For material changes, we will provide notice by website posting, email, system notice, or another reasonable method. Your continued use of the Service after the effective date means you have read the updated Policy. Where law requires separate consent, we will obtain it.
15. Contact us
- Company: [Company Legal Name]
- Taiwan Unified Business No.: [統一編號]
- Responsible Person: [負責人]
- Registered Address: [登記地址]
- Email: [聯絡 Email]