개인정보처리방침

What easy-gogo collects, why, who it is shared with, and what you can do about your own data.

Effective date2026-09-21

This page is available in Traditional Chinese and English only. In case of any discrepancy, the Traditional Chinese version prevails.

1. Scope and controller

This policy applies to easy-gogo (www.easy-gogo.com), operated by Easy Trust Information Co., Ltd. (“Easy Trust”), including the public discovery and provider pages, the customer marketing workspace, and the data interfaces made available to AI agents. Easy Trust is the controller of the personal data described below.

Customer and lead records that you create inside the workspace are data you collect yourself. For those records you are the controller, and Easy Trust only provides the tools that store and process them on your instruction.

2. Data we collect

We collect only what is necessary for the feature you use.

  • Account: email, name, company or brand name, and a securely hashed password. We never store plain-text passwords. Accounts created with Google or LINE have no password at all.
  • Social sign-in: the provider’s account identifier, email, and display name (see sections 4 and 5).
  • Brand knowledge base: the brand description, products and services, FAQs you enter, and the images and videos you upload.
  • Customer and lead records: entered by you; the content is your choice.
  • Social lead radar: when you enable it, authorized channels provide available comments on recent posts. We retain platform/account identifiers, author identifiers and names, comment text, time, and source links to identify needs and create leads, explainable scores, and follow-up tasks. We do not retrieve liker lists, private messages, or individual website browsing records, infer contact details, or merge identities across platforms. Channel tokens are also used for this server-side reading.
  • Social channel authorization: Meta OAuth retrieves your authorized Pages, linked professional Instagram accounts, and app-scoped user identifier. Account choices and tokens are encrypted temporarily for up to ten minutes; only your selected channel is retained after confirmation. LINE and advanced manual connections use tokens you supply. Credentials are encrypted with AES-256-GCM, used only on the server to verify connections and publish, and never returned to the browser.
  • Site audit: the URL you enter, together with the public page content we fetch from it and the resulting findings.
  • Reports you import: the contents of the Search Console CSV files you upload.
  • Technical and security logs: IP address, browser and device information, access time, errors, and anti-abuse data. IP addresses used for rate limiting are stored as hashes, not in their original form.
  • Public provider page statistics: only “which page, which day, how many times” (views, match hits, AI lookups). We do not record the visitor’s IP address or browser identifiers.
  • Analytics: public pages load Google Analytics when the platform has configured it. The signed-in private workspace loads no analytics at all.

3. Purposes

We use the data to:

  • create and maintain your account, session, and workspace content;
  • generate marketing drafts, run site audits, and publish the social posts you request;
  • serve your public provider page once you submit it and it is approved;
  • provide statistics and support, and send essential service and security notices;
  • detect abuse and protect the security and quality of the service; and
  • comply with applicable law.

4. Google account sign-in and Google user data

The service offers “Sign in with Google”. If you choose it, Google provides us with the data below after obtaining your consent. If you do not use it, we receive no Google user data at all.

  • Scopes accessed: only the basic openid, email, and profile scopes. Of these we actually use your Google account identifier, email address, and name. We neither request nor can read your Gmail messages, Drive files, contacts, calendar, or any other Google service content.
  • How we use it: solely to create or sign you in to your account on this service, to identify you, and to show your name and email in the workspace.
  • What we store: your Google account identifier, the email address at the time of linking (so a later sign-in maps to the same account), and your name. We do not store your Google password, nor any Google-issued access or refresh tokens.
  • Sharing: we do not sell or trade Google user data, and do not provide it to third parties for advertising or marketing. We disclose it only where required by law or a competent authority.
  • Limited use: our handling of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
  • Unlinking: you can unlink Google under “Workspace → Settings → Sign-in methods” (set a password or keep another sign-in method first so you do not lose access), or remove this service from the third-party access page of your Google account. Once unlinked, we delete the link record.

5. LINE account sign-in and LINE user data

The service offers “Sign in with LINE”. If you choose it, LINE provides us with the data below after obtaining your consent. If you do not use it, we receive no LINE user data at all.

  • Scopes accessed: only openid and profile. An email address is obtained only where we hold LINE’s email permission and you separately consent. We do not read your chat messages, friend list, or group information.
  • How we use it: solely to create or sign you in to your account and to identify you.
  • What we store: your LINE user identifier and display name, plus the email address where you consented to provide it. We do not store LINE-issued access tokens.
  • Where no email is provided: we assign a placeholder address for identification only (ending in @no-email.easy-gogo.com) that cannot receive mail, and ask you in the workspace to supply your own email so we can reach you when needed.
  • Unlinking: you can unlink LINE under “Workspace → Settings → Sign-in methods” (set a password or keep another sign-in method first). Once unlinked, we delete the link record.
  • The separate feature “connect your own LINE Official Account to publish posts” is unrelated to sign-in; it uses the Channel access token you supply yourself. See section 7.

6. Public provider pages: what becomes public

You may submit your brand information for review in the workspace. Once approved by the platform, the provider page is public content: anyone can view it, search engines may index it, and AI agents may read it through the interfaces this site offers (llms.txt, the Match API, MCP) and cite it in their answers.

Please put only information you are willing to publish on a public provider page. Do not include national identification numbers, financial account numbers, other people’s personal data, or anything that should not be public. You can edit and resubmit the page at any time, or contact us to take it down.

Content that has not been submitted or approved is not shown publicly, and your customer records, drafts, and media files are not made public along with the page.

7. Third-party services and credentials you supply

To complete the actions you trigger, data is sent to the third parties below, limited to what that action requires.

  • AI providers: after AI content generation is enabled for your account, pressing “generate” sends brand materials and instructions to the AI provider and returns a draft for review. Signed-in users can also choose website analysis during onboarding without individual AI content access. When you press “analyze website”, we read the public homepage and up to two related pages; if the platform has configured AI, extracted text is sent to OpenAI to suggest brand information, audiences and services. We retain suggestions and source URLs, not the original web pages. Suggestions become brand information only after you confirm and save them; they are not automatically published.
  • When social lead radar and AI access are enabled, comment text and limited brand materials are sent to OpenAI for intent analysis. Reply generation also uses these materials. Scores prioritize follow-up and are not conversion probabilities; only text you confirm for immediate or scheduled delivery is sent to the social platform. If AI is unavailable, the interface identifies the rule-based assessment or reply template.
  • Social platforms: when you publish, the post text and media are sent to Facebook, Instagram, or LINE as you configured. Those platforms handle data under their own policies. You can remove channels in the workspace or revoke authorization or request deletion through Meta. After verifying a Meta callback, we remove the corresponding channel credentials, account links, and pending choices. Your platform account and self-created content remain. Backups expire under our retention policy.
  • Websites you audit: an audit fetches the pages of the URL you provide as a public visitor, which may leave a record of our request in that site’s server logs.
  • Hosting, email, and analytics providers: they process data only as necessary to provide the service and must apply reasonable confidentiality and security measures.
  • Providers may process data outside Taiwan. We do not sell personal data and do not provide your workspace content to third parties for advertising.

8. Retention and security

Data is retained while your account exists and for any period required by law. After termination we delete or de-identify it within a reasonable time, except where retention is necessary for legal obligations or to resolve disputes.

We apply access control, encrypted transport, password hashing, encryption of social tokens, rate limiting, and backups. No transmission or storage over the internet can be guaranteed absolutely secure.

If you enable browser push, encrypted subscription endpoints and keys are stored and used with your browser push provider for due-task reminders. Lock-screen notifications contain no lead names or comment text. You may disable this browser subscription at any time. Confirmed public/private reply text, schedules and delivery outcomes are retained with the source comments; clearing the source removes these records but cannot retract messages already sent.

Radar comments are kept for the latest thirty days and expired comments are removed by background cleanup. You may pause collection or clear a source. Clearing the source, removing the channel, or a verified Meta revocation/deletion notification removes that source’s comments, automatically created leads, analyses and follow-up records. Deleting one lead retains a hash of the source author identifier to prevent rediscovery; clearing the source also removes that exclusion. Analysis summaries and saved follow-up records remain until you clear the data or terminate the account. Backups expire under the existing retention policy.

9. Your rights

Subject to applicable law you may request access, a copy, correction or supplementation, cessation of collection, processing or use, and deletion of your personal data. Most account data can be viewed and edited directly in the workspace; to delete an entire account, contact us using the details below.

Where data is necessary to perform a contract, protect security, or meet a legal retention requirement, we may limit part of a request after explaining why.

10. Cookies and external links

We use a cookie to keep you signed in to the workspace, a cookie to remember your language preference, and a short-lived (ten-minute) cookie that secures social sign-in and Meta channel authorization. Analytics cookies are used only on public pages and only where analytics is configured. You can manage cookies in your browser, but disabling essential cookies makes signing in impossible.

When you choose to register from an audit result, an encrypted cookie retains the website URL and check summary for up to one day so you can continue after registration or social sign-in. The summary is saved in your workspace only after you sign in and confirm the website. We do not store the original HTML fetched for the audit.

The service may link to third-party or provider-owned websites, whose data handling is not covered by this policy.

11. Contact and updates

To exercise your rights or ask about personal data, email [email protected] or call 03-5827637.

Material changes to this policy will be announced on this page together with an updated effective date.