This Privacy Policy explains how site.com.tw ("we" or "us"), a Taiwan-based service providing short links, dynamic QR codes, landing pages, digital business cards, and traffic analytics (collectively, the "Service"), collects, processes, and uses your personal data. By using the Service, you acknowledge that you have read and agree to this Policy.
1. Data Controller
The data controller under this Policy is site.com.tw, currently operated independently by an individual developer under the name "Hyphen Network" (not yet incorporated as a company or registered business; no business registration number).
2. Purposes of Collection
We collect personal data solely for the following purposes:
- Providing and operating the account system (registration, login, email verification);
- Providing core features: short link generation and redirection, dynamic QR codes, landing page editing, digital business cards (vCard), and synchronized posting;
- Providing traffic analytics (scan, view, CTA click, and conversion-funnel statistics) so you can measure the performance of content you create;
- Sending transactional notifications required for the Service (password reset emails, subscription confirmation and unsubscribe notices);
- Detecting and filtering automated bot traffic to maintain analytics data quality and service security;
- Managing usage quotas under the free plan;
- Fulfilling legal compliance obligations and handling customer support and disputes.
We do not use your personal data for any purpose beyond those listed above, do not use third-party advertising trackers or pixels, and do not sell, rent, or resell your personal data to any third party.
3. Categories of Personal Data Collected
Depending on which features you use, we may process the following categories of data:
- Account data: email address, password (stored as a hash — we neither store nor have access to the plaintext), and email verification status (handled via Better Auth).
- Service content data: the destination URLs of the short links you create, QR code configurations, landing page content, and digital business card information. This content is entered by you; if it contains personal data about you or a third party (e.g., a customer's contact details), you are the data controller for that data, and we act solely as a processor storing and handling it to provide the Service.
- Traffic analytics data: a "daily-rotating session hash" that anonymously identifies visits — computed as
sha256(secret key + current UTC date + domain + visitor IP + User-Agent), rotated automatically every UTC day. We do not store the raw IP address or User-Agent string — only this hash is persisted in our database, together with the associated scan/view/CTA-click/conversion event timestamps and aggregate statistics. - UTM forwarding: when a short link is clicked and redirected, if the original link already carried UTM parameters, we forward them as-is to the destination URL so you can track performance in the destination site's own analytics tools; we do not separately collect or retain these UTM values.
- Bot flag: we use the open-source package
isbot, which classifies a visit as automated traffic based on User-Agent pattern matching (e.g., known search-engine crawlers). This is used solely to exclude bot traffic from analytics reports and does not involve identifying or personally tracking any individual. - Email subscriber data: subscriber email address, subscription source, and associated tenant.
- Correspondence data: email content arising from customer support interactions and password resets.
4. Legal Basis for Processing
Under Article 19 of Taiwan's Personal Data Protection Act, we process the above personal data primarily on the following grounds:
- Performance of a contract: registering an account and using the Service constitutes a service contract between you and us; processing account and service-content data is necessary to perform that contract.
- Consent: for the email subscription feature, we rely on your affirmative consent given at the time of subscription, which you may withdraw at any time.
- Other processing necessary for legal compliance or preventing misuse of the Service is carried out under other applicable statutory grounds.
5. Retention Period, Region, Recipients, and Method of Use
- Retention period: data is retained for the duration of your active account. Upon account deletion, we will remove the associated personal data within a reasonable period, except where retention is required by law. Subscriber data is deactivated and removed per our internal retention policy once you unsubscribe.
- Region: our primary database is hosted in Singapore (Neon Postgres, ap-southeast-1 region); other subprocessors handle data in the regions described in their own privacy policies.
- Recipients: other than the third-party processors listed below, we do not share your personal data with any other party, and we do not use it for purposes beyond those stated in this Policy.
- Method: data is collected, processed, transmitted, and stored electronically.
6. Third-Party Processors
We engage the following service providers to process certain data on our behalf; each is separately bound by its own privacy policy:
| Provider | Purpose | Data processed |
|---|---|---|
| Neon (Neon Postgres) | Database hosting (Singapore, ap-southeast-1) | Account data, service content data, traffic analytics hashes/statistics, subscriber list |
| Resend | Transactional email delivery | Recipient email address, email content (password reset, subscription notices) |
| Vercel | Application hosting and CDN | Request handling required to run the Service; does not include the raw IP/UA data we explicitly do not store |
| Polar (Polar Software Inc.) | Payment processing for paid subscriptions, acting as Merchant of Record | Subscriber email, billing information; card details are handled directly by Polar and its payment processor (Stripe) — we never see or store your full card number |
We do not use third-party advertising networks, tracking pixels, or marketing SDKs, and we do not license any data to data brokers for resale.
7. Cookies and Tracking Technologies
- The Service uses a functional cookie (a login session cookie generated by Better Auth) solely to maintain your logged-in state — a technically necessary cookie for the Service to function.
- Traffic analytics use the daily-rotating hash design described in Section 3. This design lets us provide deduplicated visit/scan statistics without ever storing raw data (IP, User-Agent) that could identify a visitor. Because the hash input changes with each new UTC date, hashes generated for the same visitor on different days cannot be correlated back to one another.
- We do not use third-party advertising cookies, do not conduct cross-site behavioral tracking, and do not build advertising audience profiles.
8. Data Security
We apply reasonable technical and organizational measures to protect your personal data, including password hashing and TLS encryption in transit. No method of electronic transmission or storage, however, can be guaranteed to be completely secure.
9. Your Rights
Under the Personal Data Protection Act, you have the right, with respect to personal data we hold about you, to: inquire about or review it, request a copy, request supplementation or correction, request that we cease collecting, processing, or using it, and request deletion.
To exercise these rights, please email business@hyphen-network.com. If the personal data you wish to act on is embedded in content created by another user (e.g., a third party's contact details on someone else's digital business card), that user is the data controller for that data — we recommend contacting them directly, though we will assist in facilitating contact or handling the matter as required by law.
10. Consequences of Not Providing Data
If you do not provide an email address, you will not be able to complete account registration or use any feature that requires login (short links, QR codes, landing pages, digital business cards, traffic analytics, or synchronized posting). If you decline to provide data for the email subscription feature, you simply will not receive subscription notices; other Service features remain unaffected.
11. Protection of Minors
Persons under seven years of age may not use the Service. Persons between seven and eighteen years of age must obtain the consent of a legal guardian before using the Service. If we become aware that a minor has provided personal data without the required guardian consent, we will delete that data as required by law.
12. Changes to This Policy
We may revise this Policy from time to time. Material changes will be announced on our website and, where appropriate, communicated by email. We encourage you to review this page periodically.
13. Supervisory Authority and Complaints
If you have concerns about this Policy or how we handle your personal data, in addition to contacting us, you may also file a complaint with the relevant supervisory authority as provided by law.