MiniCenter Privacy Policy
Version: 2026-07-29
MiniCenter is operated by Otus, Inc. (角鴞股份有限公司), Taiwan unified business number 90232847, at 新北市新莊區新樹路244巷6弄18號. Contact legal@otus.tw for privacy questions or rights requests.
1. Scope and roles
We determine the purposes for Platform Account, Credential, registration, platform security, and audit data. A Project Backend determines purposes for its memberships, orders, and other business data. MiniCenter supplies platform capabilities under those directions while retaining its own security, fraud-prevention, and legal responsibilities. Each Project Backend remains responsible for its own notice.
2. Sources and categories
Data may come directly from an account holder, from an identity provider selected by the account holder, from a Project Client or Project Backend, or from automatically generated technical activity. Categories include email, password setup, legal acknowledgements, support content, provider subject, verification status, necessary profile fields, IP address, time, device and browser signals, sessions, security events, operations, and delivery records. A matching email alone does not automatically merge identities.
3. Purposes
We process only data needed to establish, verify, and maintain Platform Accounts; provide login, OIDC, and requested platform functions; protect account security and prevent fraud or abuse; handle transactions, notices, support, and privacy requests; comply with law and resolve disputes; and operate, debug, size, and improve reliability with minimum necessary data. Marketing, non-essential analytics, or another optional purpose requires separate revocable consent.
4. Cookies and similar technologies
The initial service uses only browser state necessary for sessions, CSRF and replay defense, federation, Cloudflare Turnstile, and Project Client-scoped advertising frequency. It has no non-essential analytics cookies, tracking pixels, or legal-notice open and click tracking, so it does not display a false cookie-consent banner.
5. Provider Disclosures
Necessary cross-border processing may occur. The table states the purpose, data categories, possible processing regions, and retention basis for each material provider.
| Provider | Purpose | Data categories | Possible processing regions | Retention basis |
|---|---|---|---|---|
| Google Cloud | Application runtime, file storage, backups, and security records | Account and service-request data, File Objects, technical and security records | Selected Taiwan region and other locations used for Google support and security operations | Account or service lifetime, backup rotation, and security investigation |
| Cloudflare Turnstile | Bot and abuse prevention | IP, browser or device signals, challenge result, and time | Cloudflare global network and support locations | Verification, abuse prevention, and the provider's limited policy period |
| Mailgun | Transactional, security, and legal mail and replies | Sender and recipient addresses, message content, delivery, bounce, and time data | Configured Mailgun region and necessary support locations | Delivery, bounce handling, cases, and required legal retention |
| ECPay | Payment, refund, and legally required electronic invoice processing | Transaction ID, amount, status, and necessary buyer and invoice data; its hosted interface handles full card data | Taiwan and any location lawfully used by ECPay | Transaction, accounting, tax, dispute, and statutory retention |
| Account-holder-selected identity providers | Google, Apple, GitHub, Facebook, LINE, or reviewed OIDC login | Provider subject, verification state, and necessary account-holder-authorized profile data | Infrastructure and support locations published by each provider | Identity Link lifetime, security investigation, and provider policy |
We review privacy impact and the need to update this Policy before adding a material provider that processes personal data.
6. Disclosure limits
We disclose minimum necessary data only for an account-holder-requested Project Client or Project Backend flow, a bound service provider, valid legal process, urgent protection from significant harm, or a company transaction subject to confidentiality and continued purpose limits. MiniCenter does not sell personal data, rent contact lists, or create advertising profiles across Project Clients.
7. Retention and deletion
Account and verification data remains through account deletion and necessary recovery completion. Sessions, risk, security, support, and privacy-case data use limited periods based on their purposes. Payment, invoice, accounting, and tax records follow applicable law. Pending registrations and exports are short-lived. Terms Acceptance, Privacy Notice Acknowledgement, and Age Eligibility Attestation remain for no longer than 15 years after Account Deletion, then are deleted or irreversibly anonymized. Backups expire by rotation. A Legal Hold must have a scope, reason, owner, audit trail, and expiry.
8. Individual rights
A Platform Account holder may request access, export, correction, Account Deletion, or stopping specific collection, processing, or use. Logged-in account holders reauthenticate; people unable to log in use minimum necessary manual verification through legal@otus.tw, and an email address alone is insufficient. Optional processing can be withdrawn. Processing necessary for account operation, security, fraud prevention, service delivery, or law instead requires account restriction or Account Deletion.
We normally acknowledge a request within seven calendar days and complete it or provide progress within thirty calendar days after verification, with one notified extension where necessary. A MiniCenter export does not pretend to contain all business data controlled by Project Backends and provides the relevant request route.
9. Security incidents
When a personal-data or significant security incident may affect account holders, we notify as required by law after enough initial confirmation. The notice describes known scope, likely effect, response, recommended action, and contact route and may be updated as investigation continues without exposing harmful detail or another person's data.
10. Changes and contact
Material changes normally receive 30 days notice by email and in-product message. A legal, security, or anti-abuse emergency may use a shorter period with a recorded reason. Delivery is not proof of reading, agreement, or acceptance. Contact legal@otus.tw.
The Traditional Chinese version prevails; this English version is a translation.