Privacy Policy
Version v1.5 | 2026-09-30 | Established pursuant to Articles 7 and 8 of the Personal Data Protection Act
Taoyuan City Vision Association (hereinafter “the Association”) respects and protects your personal data. This policy explains what data the Association’s official website collects, how it is used, how long it is kept, and what rights you may exercise.
This policy applies only to this website. For links on this website leading to other websites, the privacy practices of those websites are the responsibility of each respective site.
1. What data we collect
Data you provide yourself
- Contact telephone number (optional): obtained only when you enter it yourself in the Member Center.
- Event registration information: when you register for an event, the Association records which event you registered for, the time of registration and its status.
- Your membership and subscription choices: whether you have become a website member, whether you consent to receiving event and offer messages, and a record of each time you change or withdraw these choices.
- Bank transfer reports from paid website members: after you pay the annual fee for paid website membership by bank transfer, the payment date, amount, last five digits of the remitting account number and notes that you enter when reporting it in the Member Center. The last five digits are used solely for the Association to verify the payment, and are deleted from the website once the Association confirms or returns that report, or once you withdraw it yourself.
Data obtained through social account login
This website uses a LINE, Google or Facebook account as the means of login, with your own choice of one of them; those who log in with a Google or Facebook account may additionally link a LINE account to the same member identity. When you authorize login or linking, the Association obtains the following from that platform:
- Your display name
- The URL of your profile picture
- Your email address (requires your consent to provide it on the authorization screen)
- That platform’s user identifier (a code used to recognize you as the same member)
In addition, when you log in with LINE or link a LINE account, the Association queries LINE as to whether you are a friend of the Association’s LINE official account — this is a condition for becoming a website member (see the Terms of Service). When you add or remove the Association’s official account as a friend, the Association also receives a notification from LINE and updates this status accordingly. The only thing the Association obtains is the single status of “whether you and the Association’s official account are friends”.
The Association obtains only the items listed above. The Association does not obtain your list of friends or contacts, your posts, your chat content, or any other data from that platform account.
Data generated automatically by the system
- Member number: a code assigned by the system when you become a website member (for example
V26-K7M3Q). It does not contain your name, date of birth or contact details. - Login session records: including the time of creation, the validity period, and the browser identification string (user agent) used when you logged in. This is so that you can stay logged in, and so that problems can be investigated if anything unusual occurs.
- Consent records: the time of each consent or withdrawal, the policy version in force at the time, the source page, the connecting IP address and the browser identification string. This is so that, in the event of a later dispute, it can be shown what you consented to and which version applied.
- Friend status records: the times and event records of your adding or removing the Association’s LINE official account as a friend. This is the basis for determining membership eligibility, and also allows the status at the time to be verified in the event of a later dispute.
- Annual fee registration records: the payment date, amount and paid validity period recorded by the Association after confirming payment, together with the administrator who recorded it and the time of recording. This is the basis for the validity period of paid website membership, and also allows verification in the event of a later dispute.
- Connecting source IP address: used for rate limiting, to prevent the service from being overwhelmed by large volumes of automated requests.
- Traffic statistics: when you visit this website, the system records the page path visited, the referring website, and whether a mobile device was used, in order to understand how the website is being used. These statistics do not identify you personally: the Association does not store your connecting IP address in the traffic statistics, but instead converts the IP address and browser identification string, together with the date of that day, into a code that cannot be reversed, used solely to determine “whether this visitor has already been counted today”. Because the code contains the date of that day, the same visitor receives a different code on different dates, and the Association cannot use it to track your browsing behavior across days. If your browser has Global Privacy Control (GPC) or Do Not Track (DNT) enabled, the Association does not record this.
What we do not collect
- This website does not handle payment flows, and does not collect credit card numbers, full bank account numbers or images of passbooks. Annual fees are paid to the Association by bank transfer, and the accounting records of those payments are kept separately by the Association as required by law, not on this website.
- This website has no third-party analytics or advertising tracking tools installed. The traffic statistics described above are calculated by the Association itself in an anonymous manner, and the data is not transmitted to any third party.
- The content of conversations with the AI customer service is not stored. Your questions are not retained in the Association’s systems once a reply has been generated.
2. How we use this data
- To identify you as a member and maintain your login status
- To process event registrations and, where necessary, contact you about matters relating to an event
- To verify bank transfers of annual fees from paid website members and to record the paid validity period
- To send event and offer messages, where you have consented
- To group recipients according to your participation, so that the messages you receive are more relevant to your interests
- To maintain the security and proper operation of the website and its services
The Association does not sell, lease or exchange your personal data with third parties, nor use it for purposes unrelated to those stated above.
3. Where we keep the data
- Member data and registration records are stored in the database service provided by Cloudflare.
- The login function is provided by the platform you choose — LINE (LY Corporation), Google (Google LLC) or Facebook (Meta Platforms, Inc.); your act of authorization is subject to each platform’s own privacy policy.
The Association uses the database service provided by Cloudflare, and the data actually runs in its Asia-Pacific (APAC) data centers, which may not be within the Republic of China. By using the Association’s membership and event registration services, you acknowledge that the Association will transmit and store the necessary personal data outside the country, within the scope of the purposes stated above.
4. What partner merchants can see about you
The Association negotiates merchant offers for members. When you make a purchase at a partner merchant and use an offer, you need to present your member number or member QR code to show that you are a member.
- What the merchant sees is your member number. As noted above, that number does not contain your name, contact details or purchase history.
- The Association currently does not provide any system or interface allowing partner merchants to look up member data. Merchants have no way of obtaining your other data through that number.
- Your purchases, bookings and payments at a partner merchant are handled directly by that merchant; the Association does not handle them and does not obtain the related data.
Should merchant-side lookup or redemption functions be made available in the future, the Association will first revise this policy and give separate notice; the scope of what merchants can see will not be expanded without your knowledge.
5. Marketing messages and your choices
- Receiving event and offer messages is optional. Declining to receive them does not affect your membership, nor does it affect your ability to register for events.
- Consent is requested separately for the email and LINE channels, and may also be withdrawn separately. You may keep only one of them.
- You may change this at any time in the Member Center, or simply click the unsubscribe link in each message. After withdrawal, the Association will stop sending marketing messages through that channel.
- Withdrawing marketing consent does not affect necessary transactional notices. You will still receive messages directly related to your own actions, such as event registration confirmations and notices of changes to or cancellation of an event. Such messages are part of the Association’s performance of its services and are not marketing messages.
6. Retention periods
- Member data: kept for 3 years from your last login. Where you have not logged in again within that period and have not taken part in any event, the Association will delete or de-identify the data. You may also request earlier deletion at any time.
- Event registration records: kept for 5 years from the end of the event, for use in event settlement, outcome reporting and statistics.
- Consent records: deleted at the same time as the personal data concerned. The purpose of these records is to show what you have consented to, and they are therefore not deleted separately, nor overwritten, for as long as the data exists.
- Friend status records: the same as consent records — deleted at the same time as the personal data concerned, and not deleted separately or overwritten for as long as the data exists.
- Annual fee registration records and bank transfer reports: deleted at the same time as the personal data concerned, and not deleted separately or overwritten for as long as the data exists. Of these, the last five digits of the remitting account number are deleted as soon as the report in question has been processed (confirmed, returned or withdrawn).
- Login sessions: automatically expire and are cleared once the validity period has elapsed.
- Connection records used for rate limiting: stored temporarily for a short period and cleared automatically on expiry.
- Traffic statistics: the daily aggregate figures (for example, “how many page views there were on a given day”) are kept long term as an operating record of the Association; the page and referrer details are kept for 180 days and deleted automatically thereafter.
7. Use of cookies
This website uses only the cookies necessary to maintain basic functions, and has no advertising or tracking cookies:
| Purpose | Description |
|---|---|
| Login status | Records your login session so that you do not have to log in again for every action |
| Login process protection | Exists briefly during the login process (ten minutes), used to verify that the request comes from you and to prevent cross-site attacks |
You may block cookies in your browser settings, but if you do, the login and registration functions will not be available.
8. Your rights
Under the Personal Data Protection Act, you may exercise the following rights in respect of your personal data held by the Association:
- To make inquiries or request review
- To request a copy
- To request supplementation or correction
- To request that collection, processing or use be discontinued
- To request deletion
Some data you can view and change yourself directly in the Member Center. For the rest, please contact the Association using the contact details below, and the Association will respond within a reasonable period.
Please note: if you request the deletion of your personal data or that its use be discontinued, the Association will be unable to continue providing membership and event registration services.
9. Minors
If you are under eighteen years of age, please use the membership and event registration functions of this website only after your parent or guardian has read, understood and agreed to this policy. If the Association discovers that a minor has provided personal data without such consent, it will delete the data after verification.
10. Revisions to this policy
The Association may revise this policy in response to changes in law or in its services. Revisions will be announced on this page, and the version number at the top of this page will be updated. For significant changes affecting your rights, the Association will give separate notice through a channel you have consented to.
11. Contact us
If you have any questions about this policy or about your personal data, please contact the Association:
- Organization: Taoyuan City Vision Association
- Email: service@vision.org.tw
- Telephone: 03-4351236
- Fax: 03-4351211
- Address: 4F, No. 556, Sec. 2, Zhongshan E. Rd., Zhongli Dist., Taoyuan City