Privacy Policy
Effective date: 2026-09-01
三次方研究室有限公司 CubeLab Ltd. (Business ID: 95481008, "MeFresh", "we", "us", or the "Company") respects personal data. This Policy applies to MeFresh business accounts, the App, dedicated Business booking pages, support, payments, and related services.
1. Scope and Privacy Roles
This Policy covers Businesses and their Members, as well as customers who create an account or book through a dedicated Business booking page.
MeFresh determines processing purposes for business accounts, subscription billing, support, security, notifications, and its own product analytics. For customer data, photos, service records, and signatures entered by a Business for its operations, the Business is the primary collecting party and MeFresh generally acts under its instructions.
2. Data We Collect
- Business and account data: name, studio name, email, phone number, credentials, Google identifiers, settings, members, and permissions.
- Booking Customer and booking data: name, email, phone number, Google or LINE LIFF identifiers, booking time, service, Business-defined fields, status, and communications.
- Service and transaction records: free-text notes, photos, service-confirmation signatures, checkout signatures, receipt images, products, stored value, class packages, coupons, and checkout records.
- Payment data: status, amount, time, order number, and transaction identifier. We do not store full card numbers, security codes, LINE Pay passwords, or complete payment credentials.
- Device and technical data: IP address, device model, operating system, App version, language, push token, login time, errors, and security logs.
- Usage and analytics data: feature interactions, screen views, usage time and frequency, and related product events.
- Support data: messages, attachments, requests, and resolution records submitted through official LINE, email, or support channels.
Camera and photo-library access is used only when a user chooses to capture or upload an image. Notification access is used for booking, payment, security, and service notices. Refusing a permission affects only the related feature.
3. Sources
- Businesses, Business Members, or Booking Customers directly.
- A Business entering or uploading data for a Booking Customer.
- Google, LINE, Apple, NewebPay, or another service selected by the user.
- Automatically when the App, booking pages, support, or payment processes are used.
4. Purposes
- Create and manage accounts, verify identity, and provide login.
- Process bookings, customer management, service records, signatures, checkouts, receipts, and studio functions.
- Process subscriptions, employee capacity, payment status, refunds, accounting, and support.
- Send booking, payment, renewal, security, service-change, and push notifications.
- Protect security, prevent fraud and abuse, debug, back up, and recover the Service.
- Use Google Analytics, Mixpanel, and internal statistics to understand feature use and improve the product.
- With separate consent or another lawful basis, send MeFresh product updates and marketing to Business users. We do not directly market MeFresh to Booking Customers.
- Perform contracts and legal duties, handle complaints and disputes, and establish, exercise, or defend legal claims.
5. Period, Regions, Recipients, and Methods
Period
Data is used while the account, contract, or stated purpose remains active, and afterward as needed for legal duties, billing, security logs, backup cycles, complaints, disputes, or legal claims. When no purpose or need remains, data will be deleted, processing will stop, or the data will be de-identified.
Regions
Data may be processed in Taiwan and vendor locations, including the United States for Heroku and Heroku PostgreSQL and the Asia Pacific (Tokyo) region for AWS S3. Other vendors may process data internationally through their infrastructure.
Recipients and methods
Data is processed by automated or non-automated means and may be accessed, where necessary, by authorized MeFresh personnel, the relevant Business and its authorized Members, contracted vendors, and legally authorized authorities.
Effect of not providing data
You may decline optional data. If information required for an account, booking, payment, security verification, or support is not provided, the corresponding process or feature may not be available.
6. Vendors and International Transfers
MeFresh does not sell or rent personal data. We use vendors only as needed to provide the Service and require appropriate contractual and legal safeguards:
- Cloud and storage: Heroku, Heroku PostgreSQL, and Amazon Web Services S3.
- Login and communications: Google, Gmail, LINE, LINE LIFF, LINE Messaging API, and Firebase Cloud Messaging.
- Analytics: Google Analytics and Mixpanel.
- Payments and subscriptions: NewebPay and Apple App Store. Customer LINE Pay payments use the Business's own LINE Pay merchant account.
International transfers are limited to hosting, storage, backup, login, communications, analytics, payment, and security purposes. We apply reasonable safeguards based on data sensitivity, vendor terms, and available technology.
7. Sensitive Content Entered by Businesses
Business-entered free-text service records may contain photos, allergies, medical history, or other health-related information. MeFresh does not require unnecessary health data. The Business must establish necessity, give required notice, and obtain legally sufficient written consent.
Businesses must not enter full identity-document copies, complete card data, payment passwords, account passwords, or unrelated high-risk data. Booking Customers with questions about Business-entered content should first contact the Business or ask MeFresh for assistance.
8. Analytics
We use Google Analytics and Mixpanel for product and technical events. Analytics data should not contain a Booking Customer's name, phone number, email, photos, signatures, or free-text service records.
The App does not currently provide one unified product-analytics opt-out. Device, operating-system, or vendor controls may limit some tracking. We will update these controls as features and legal requirements evolve.
9. Sharing and Disclosure
- At your direction or with your consent.
- To the relevant Business, its Members, and contracted vendors as needed to provide the Service.
- To comply with lawful court or government requests or protect MeFresh, users, and third parties.
- Under confidentiality and safeguards in a merger, reorganization, investment, or business transfer, including to advisers and a successor, with notice where required.
10. Security and Incidents
We use reasonable technical and organizational measures proportionate to data sensitivity and risk, including access controls, transmission protection, backups, logging, and security monitoring. No system can guarantee absolute security.
If a personal-data incident occurs, we will investigate, contain the impact, remediate, and notify affected individuals or authorities as required by applicable law.
11. Retention, Downgrade, and Deletion
When a Business downgrades to Lite, existing customer, booking, transaction, product, stored-value, package, and employee data remains stored. The Business may view and export past Pro data but may not add, edit, or operate Pro-only functions.
Account deletion currently uses soft deletion: the account is immediately disabled and ordinary access stops. Data may remain where necessary for law, security, fraud prevention, disputes, backups, disaster recovery, or other legitimate operational needs. When the purpose ends, we will delete, stop processing, or de-identify data as required by law.
12. Your Rights
Subject to applicable law, you may request access, copies, supplementation or correction, cessation of collection, processing, or use, and deletion. We may verify identity and scope before responding.
We generally decide access or copy requests within 15 days and correction, cessation, or deletion requests within 30 days. Lawful extensions may apply with notice. Necessary costs may be charged for copies.
For records created by a Business, we may refer the request to or coordinate with that Business. Deletion or cessation may be limited where retention remains necessary for law, contract, billing, security, or disputes.
13. Marketing and Service Notices
Payment, booking, account-security, renewal, and service-change messages are necessary service notices. MeFresh marketing is directed only to Business users and is sent only with consent or another lawful basis. We do not use Booking Customer data to market MeFresh directly.
Business users may opt out of marketing at no cost through the message, official MeFresh LINE account, or sup.mefresh@gmail.com. Opting out does not affect necessary service notices.
14. Updates and Contact
We may update this Policy for legal, service, data-flow, or vendor changes. Material updates will generally be emailed to Businesses at least 30 days before taking effect. A new use that legally requires consent will receive separate consent.
- Company: 三次方研究室有限公司 CubeLab Ltd. (Business ID: 95481008)
- Contact: Official MeFresh LINE account
- Email: sup.mefresh@gmail.com
The English version is provided for reference. The Traditional Chinese version controls in case of conflict.
© Copyright 2026 - All Rights Reserved by 三次方研究室有限公司 CubeLab Ltd. (95481008)