Privacy Policy
Last updated September 14, 2026
This policy explains how the Hallelujah Home Church website and HHC Account services collect, use, retain, and protect personal information. Please read it before using the website or creating an account.
Scope and data controller
This policy applies to the public website, HHC Account, and related online services provided through alive.org.tw and its subdomains. They are provided and maintained by Hallelujah Home Church (the Church).
If this website links to third-party websites, video platforms, social platforms, or map services, those services are governed by their own privacy policies.
Information we collect
When you contact us through a form, email, or event registration, we may collect your name, contact details, registration details, message content, and other information needed to respond to your request.
When you create or use an HHC Account, we process your email address, name, profile image, email-verification status, password hash, and security data such as multi-factor authentication secrets and backup codes. We do not store your plaintext password.
To maintain sign-in and account security, we process device identifiers, browser and operating-system details, IP addresses, sign-in and activity times, sessions, and security-event records.
When you browse this website, servers or third-party services may generate necessary technical data, such as IP address, browser information, device type, access time, browsing and click records, and error logs.
We use Sentry to detect frontend errors and performance problems. We send only de-identified error, browser, device, page-path, release, and trace data, and do not intentionally send cookies, authorization headers, form contents, or complete URL query parameters.
When you choose to receive newsletters or browser notifications, we process your language, consent and subscription status, together with the email address or encrypted browser push subscription needed to provide that service.
Third-party sign-in
When you sign in with Google, we receive your Google account identifier, verified email address, name, and profile image to create, identify, or link your HHC Account. We do not access Gmail, Google Drive, or other Google content.
When you sign in with Microsoft, we receive your Microsoft account identifier, name, and any email address Microsoft provides. When you sign in with LINE, we receive your LINE account identifier, display name, and profile image, and we do not request your email address from LINE.
If a provider does not supply an email address we can rely on, we require separate HHC email verification. We retain third-party sign-in identifiers until you unlink the provider or delete your account. Each provider handles its own data under its own policy.
How we use information
We use information only as needed to provide account and church services, verify identity and email addresses, communicate about events, respond to inquiries, operate and secure the website, prevent fraud and abuse, and improve services.
Browsing and click records are mainly used for internal analysis of traffic, content quality, and service experience, not to identify specific individuals for advertising tracking.
We do not sell personal information or provide third-party sign-in data to unrelated parties for advertising, data-broker, or marketing purposes. We do not use it outside the stated purposes unless required by law, needed to protect rights, or authorized by your consent.
Newsletters and non-essential browser notifications are sent only after you opt in. You can unsubscribe at any time through an email unsubscribe link, HHC Account notification preferences, or the website notification control. Account verification and security messages are not affected by newsletter opt-out.
Restricted content security
To provide members-only documents, protect content, and address unauthorized distribution, the Church may add security identification information linked to an HHC Account to downloaded documents and record the account identifier, bulletin issue, language, issuance time, and document-processing identifiers. The security identification information does not directly contain a name or email address. Only authorized personnel may map it to an account where necessary for these purposes.
Authorized personnel may submit a suspected distributed document or image for source review. The system records the submitter, bulletin issue, language, processing status, review result, and any matched account and issuance time. Uploaded files are deleted when the review is completed; files for unfinished cases are removed no later than 24 hours after upload. Issuance and review records are generally retained for one year and automatically deleted when that period expires. They may be retained for the necessary period when required to handle a dispute or security incident in accordance with law.
These data are used only to provide members-only documents, protect content, review sources, and handle related disputes, and are not used for advertising or marketing. Review results are assessed together with other facts. You may exercise the access, copy, correction, restriction, and deletion rights described in this policy. Choosing not to use the members-only document download service does not affect other account features, but you will not be able to obtain the restricted document.
Retention
We generally retain account information until the account is deleted or the service relationship ends. Records needed for legal obligations, security investigations, dispute handling, or audits may be retained for the necessary period.
Registration accounts that do not complete email verification are deleted 7 days after creation. Device activity records are deleted 180 days after their last activity. Other information is deleted or de-identified when its purpose ends, its retention period expires, or deletion is legally required.
Processing locations, recipients, and vendors
Information may be processed where the Church and its cloud hosting, storage, email, security, and third-party sign-in providers operate, which may involve cross-border processing.
Recipients are limited to authorized Church personnel, contracted service providers, your selected sign-in provider, and authorities legally entitled to request information. Vendors may process information only for the contracted purpose and must use appropriate confidentiality and security measures.
Cookies and local storage
We use necessary cookies or local storage to maintain sign-in and security state, recognize devices, prevent cross-site request forgery, and remember language and appearance preferences. We do not use this information for advertising tracking.
You can delete cookies or local data through your browser. Doing so may sign you out, create a new device record, or prevent preferences from being saved. If we later add non-essential analytics or advertising tracking, we will update this policy and provide any choice or consent required by applicable law.
Security and incident notice
We use reasonable technical and organizational measures, including access controls, transport protection, and hashing or encryption appropriate to the data, to reduce unauthorized access, alteration, loss, or disclosure. No online service can guarantee absolute security.
If a personal-data incident requires notice under applicable law, we will notify affected people and take necessary response measures. Please do not submit unnecessary sensitive information through public forms.
Your rights and contact
You may request access, copies, supplementation, correction, deletion, or suspension of collection, processing, or use as permitted by applicable law. You may also request to unlink a third-party sign-in or delete your HHC Account.
If you do not provide necessary information, we may be unable to create an account, verify your identity, respond to inquiries, complete event registration, or provide related services.
To exercise these rights, request account deletion, or ask about this policy or our data handling, email support@alive.org.tw. We may take reasonable steps to verify your identity before processing a request.
