Privacy Policy
Last updated: July 2026
1. Personal Data We Collect
To provide the wedding thank-you card service, CardJam (provided by OharaLab) collects the following categories of personal data depending on how you use the Service:
- Account data: When you sign in with Google or register with an email and password, we obtain your email address and display name (and, for Google sign-in, your avatar URL).
- Guest data (uploaded by the couple): When you create a project, you may upload guest names, phone numbers, blessing messages, and photos, used to generate personalized cards and to verify a guest's identity before they can view their card.
- LINE Official Account integration data: If you connect a LINE Official Account, once a guest adds it as a friend we obtain that guest's LINE user ID, display name, and profile picture URL, used for card-link broadcasts and friend list management.
- Payment transaction data: Paid plans are processed through the third-party payment gateway PAYUNi. We retain only the transaction ID, amount, and payment status — we never handle or store your credit card number or security code.
- Technical data: connection IP address and browsing activity, used for rate limiting, abuse prevention, and service security.
Retention period: personal data is used for as long as the account or project remains active; after termination, it is retained only for the period required by applicable law and then deleted or de-identified. Region of use: primarily within Taiwan; because the Service runs on Cloudflare's global content delivery network, data may be technically transmitted through Cloudflare's overseas nodes in transit, but the actual use of the data never exceeds what is necessary to provide the Service.
2. Purposes of Use
We use the personal data we collect for the following purposes:
- Providing, operating, and improving the Service, including creating and managing wedding thank-you card projects.
- Verifying guest identity, so that only the intended guest can view their own card.
- Processing payments and activating or extending paid plans.
- Sending card notifications and service-related messages via email or LINE Official Account.
- Preventing abuse and fraud and maintaining system security, including rate limiting and anomaly detection.
- Complying with legally required retention obligations and handling customer support and disputes.
3. Cookies and Tracking Technologies
The Service uses only the session cookie required to keep you signed in (httpOnly, not readable by client-side JavaScript). We do not use advertising or marketing tracking cookies, and we do not integrate third-party analytics tools such as Google Analytics.
The Service is deployed on Cloudflare, whose proxy layer automatically injects Cloudflare Web Analytics, an anonymous traffic measurement beacon. This mechanism does not use cookies and does not record information that identifies individual users — it is used only for aggregate site traffic monitoring.
4. Third-Party Services
To provide the Service's functionality, we share necessary personal data with the following third-party service providers, each of which maintains its own privacy policy — we recommend reviewing them as well:
5. Data Protection Measures
We take the following measures to protect your and your guests' personal data:
- All traffic is encrypted in transit via HTTPS/TLS.
- Account passwords are stored using a one-way hashing algorithm, never in plain text.
- Credentials required for LINE Official Account integration, such as the Channel Secret, are stored encrypted with AES-256-GCM.
- Guest card pages require a name-and-phone verification step; the admin dashboard is restricted to designated administrator emails.
- Key endpoints — login, guest verification, email delivery, file upload — are all rate-limited to prevent brute-force attempts and abuse.
- Data is stored in Cloudflare D1 (database) and R2 (file storage), protected by Cloudflare's global infrastructure security.
6. Your Rights (Personal Data Protection Act, Article 3)
Under Article 3 of Taiwan's Personal Data Protection Act, you (or your guests) may exercise the following rights over personal data held by the Service:
- Query or request access.
- Request a copy.
- Request supplementation or correction.
- Request that collection, processing, or use be stopped.
- Request deletion.
To exercise any of the rights above — whether you are a registered account holder or a guest — please contact us at card@oharalab.com. We will process your request within a reasonable time. Exercising these rights may mean certain features (such as displaying your card) can no longer be provided, and we will explain any such impact before proceeding.
7. Children's Privacy
The Service does not knowingly collect personal data from children under 13, and account registration requires full civil capacity or the consent of a legal guardian. If we become aware that we have collected a child's personal data without a guardian's consent, we will delete it as soon as possible. If you are a child's legal guardian and become aware of such a situation, please contact card@oharalab.com.
8. Policy Updates
We may update this Privacy Policy from time to time. Updates will be posted on this page and the "Last updated" date above will be revised; material changes to how we collect or use data will additionally be communicated by email to registered users. We encourage you to review this page periodically.
9. Contact Us
If you have any questions about this Privacy Policy or your personal data, please contact us:
This Policy is governed by the laws of the Republic of China (Taiwan). Any dispute arising from this Policy or the Service shall be submitted to the Taoyuan District Court, Taiwan, as the court of first instance.