Privacy Policy
Effective date: August 10, 2026
SASUGOD!Jars ("the Service") is a service under the SASUGOD platform operated by Green Signal Ltd. (綠燈有限公司, Taiwan Unified Business No. 94095438, "we", "us"), providing a personal finance tool centered on importing e-invoice data and organizing your income and expenses. We take your privacy seriously and process your personal data in accordance with Taiwan's Personal Data Protection Act (the "PDPA"). This Policy explains how we collect, use, retain, and delete personal data. By using the Service, you agree to this Policy.
1. Data We Collect
- Account data: the email address and account identifier obtained via Google OAuth sign-in, used to create and identify your account. We never receive your Google account password.
- Financial and invoice data: e-invoice data you upload or import (for example, a spending-detail CSV file exported from Taiwan's e-invoice platform, containing items, amounts, dates, and seller tax ID), manually entered transactions, categorization results, and shared family ledger data.
- Subscription and transaction data: subscription plan, purchase token, and subscription status (e.g. trialing, renewed, canceled) generated via Google Play Billing. We never handle or store your card details — all payment instruments are processed by Google Play.
- Device and usage data: app version, OS, crash logs, and basic usage behavior (login frequency, feature usage) for debugging and service improvement.
- Local storage: login tokens (access / refresh token) are stored in your device's localStorage to keep you signed in, and are not forwarded to any third party beyond our own servers.
- Phone number (account uniqueness): to ensure one account per person and prevent abuse, we collect and verify your phone number by SMS when you voluntarily link it. We store only a one-way, non-reversible hash — never the number in plaintext. Your phone number is not used for login or marketing.
2. Purpose and Manner of Collection
- Core service delivery: invoice data import and parsing, categorization suggestions, bookkeeping and reports, family ledger sharing.
- Authentication and account security: verifying identity via OAuth, maintaining login state, preventing unauthorized access.
- Subscription and payment processing: verifying Google Play purchase tokens, syncing plan and expiry status to unlock corresponding features.
- Customer support: responding to inquiries and troubleshooting (support staff only access your ledger data when necessary and authorized, and such access is logged).
- Service improvement and reliability: analyzing crash/error logs to improve recognition accuracy and system stability.
- Legal compliance: retention required under Taiwan e-invoice and tax regulations.
3. Data Sharing and Third Parties
We do not sell your personal data, nor use your financial data for third-party marketing. We share data with necessary third parties only as follows:
- Google (OAuth sign-in): used for identity verification; Google processes sign-in related data under its own privacy policy.
- Google Play Billing: processes subscription payments and receipts; payment instrument data is held by Google, and we only receive the purchase token and subscription status.
- ECPay: processes card payments and refunds for website subscriptions; card numbers are held by ECPay, and we only receive the order number, amount, and payment result.
- Cloud hosting/infrastructure providers (e.g. Vercel): used to deploy and run the Service, receiving only technical data necessary for operation.
- Legal requirements: if lawfully required by a judicial or competent authority, we will cooperate within the scope of the law.
4. Data Retention
- While your account is active: your bookkeeping data is retained for your ongoing access.
- After account deletion: you may request deletion at any time from the app's Settings or the public deletion page linked below; we delete the associated personal data immediately after verifying your identity, except transaction records required to be retained under tax/e-invoice regulations (currently up to 5 years under common practice), which remain in backend audit records until that period expires.
- Subscription/transaction records: retained until the statutory limitation period expires, to handle refund disputes and legal compliance.
5. Data Security
- All network transmission uses HTTPS encryption.
- Authentication uses JWT tokens with limited validity periods.
- Backend APIs enforce access control by identity — only you (or authorized family members) can access your ledger data.
- Support/admin staff access to user data requires authorization and is logged for audit.
6. Your Rights
Under applicable law, you may request access, a copy, correction, restriction of processing, or deletion of your personal data. To exercise these rights, contact us using the details below; we will respond within a reasonable time.
7. Account and Data Deletion
To delete your account and associated personal data, you can request deletion directly from the app under Settings → Danger Zone, or visit the public page jars.sasugod.com/legal/delete-account and sign in to submit a request. We will delete the personal data collected by this Service immediately after verifying your identity, except for data required to be retained by law as described in Section 4.
Scope: this deletion only removes data collected and generated by this Service (Jars). It does not delete your SASUGOD member sign-in identity (your Google login), which is shared across multiple SASUGOD products. If you continue to use other SASUGOD products, those services and your sign-in identity are unaffected. To delete your entire SASUGOD member identity, please contact us separately.
If you are unable to sign in to the Service, please email support@sasugod.com; we will complete deletion within 30 days of receiving and verifying your request.
Deleting your account does not automatically cancel your Google Play subscription — please cancel it separately from the Google Play "Subscriptions" page to avoid further charges.
8. Children's Privacy
The Service is not designed for, nor specifically targeted at, children under 13. If we become aware that we have collected personal data from a child under 13, we will delete it as soon as possible. If you are a parent/guardian and believe your child has provided personal data to us, please contact us using the details below.
9. Cookies and Local Storage
The Service primarily uses browser localStorage to store login tokens to keep you signed in, and does not use tracking/advertising cookies.
10. Changes to This Policy
We may revise this Policy due to legal or service changes; the "Effective date" above will be updated accordingly. For material changes (e.g. an expanded scope of data collection), we will provide additional notice within the Service.
11. Governing Law and Jurisdiction
This Policy and any disputes arising from it are governed by the laws of the Republic of China (Taiwan), with the New Taipei District Court, Taiwan as the court of first instance.
12. Contact Us
Operator: Green Signal Ltd. (綠燈有限公司) | Taiwan Unified Business No.: 94095438 | Registered address: 20F-3, No. 33, Sec. 1, Minsheng Rd., Banqiao Dist., New Taipei City 220363, Taiwan.
If you have any questions about this Privacy Policy, please contact us at support@sasugod.com, or via in-app Settings → Support & Legal → Contact / Report an issue.