Loading...
Please wait

Privacy Policy

Last updated: March 24, 2026 | Version: 1.0

This privacy policy is authoritative in Traditional Chinese. In case of any discrepancy, the Chinese version shall prevail.


I. Purpose of Data Collection

Migrant Ticket (hereinafter referred to as "this system") collects your personal data in accordance with the Republic of China Personal Data Protection Act (hereinafter "PDPA") for the following purposes:

  • Flight booking and ticket issuance operations (GDS system integration)
  • Passenger identity verification (passport and ARC verification)
  • Payment processing (account balance deduction or convenience store payment)
  • Customer service and order notifications
  • Legal compliance and audit trail retention
II. Types of Personal Data Collected
CategoryData ItemsPurpose
Account InformationEmail, name, phone, password (stored as hash)Identity verification and contact
Identity DocumentsPassport number, passport expiration date, ARC numberRequired data for GDS booking
Personal CharacteristicsDate of birth, gender, nationalityAirline booking requirements
Company InformationCompany name, Unified Business Number (for brokers/agents)B2B account management
Transaction RecordsOrder amount, payment method, account balance changesFinancial processing and reconciliation
System LogsIP address, browser information, operation logsSecurity audit and troubleshooting
III. Data Security Measures
  • Passport and ARC numbers: stored using AES-256-GCM encryption, compared using HMAC-SHA256 hash during queries
  • Password: encrypted using BCrypt one-way hash; the system cannot recover your password
  • Credit card information: this system does not store credit card numbers; payment is processed by third-party payment platforms (HiTrust/Newebpay)
  • Transmission security: the website uses HTTPS encrypted transmission
  • Access control: administrators access data according to role-based permissions; all operations are logged for audit purposes
  • Log masking: personal data (email, phone, passport number) in system logs are automatically masked
IV. Data Sharing and Third-Party Transfer

Your personal data may be transmitted to third parties in the following cases:

  • GDS systems (Amadeus / Sabre): passenger data required for booking and ticketing (data transmitted to France/United States)
  • Payment platforms (HiTrust / Newebpay): transaction information required for payment processing (data retained in Taiwan)
  • Airlines: passenger manifest and travel document data transmitted through GDS
  • Passport recognition service (Google Cloud Vision API): passport image recognition processing (data transmitted to United States, used only when local OCR confidence is insufficient)
  • Notification service (LINE Messaging API): order status push notifications (data transmitted to Japan, limited to users with linked LINE accounts)
  • Government agencies: disclosed as required by law (such as National Immigration Agency verification)

This system will not sell or disclose your personal data to unnecessary third parties.

Cross-Border Transfer Notice

For ticket booking purposes, your passenger data (name, passport number, nationality, date of birth) will be transmitted to overseas servers via GDS systems. Our company has verified that all partners have data protection measures compliant with international standards:

  • Amadeus (France/Spain): compliant with EU GDPR
  • Sabre (United States): SOC 2 Type II certified
  • Google Cloud (United States): ISO 27001 / SOC 2 / GDPR certified
  • LINE (Japan): compliant with Japan's Act on Protection of Personal Information (APPI)

Pursuant to Article 21 of the Personal Data Protection Act, our company conducts cross-border data transmission within necessary scope and has implemented appropriate security measures to protect your data.

V. Rights of Data Subjects (Article 3, Personal Data Protection Act)

You have the following rights under law:

  • Inquiry/Access: you can view your personal data stored in the system on the "Personal Data" page
  • Copying/Export: you can download all your personal data through the "Data Export" function
  • Supplementation/Correction: you can update your contact information on the "Personal Data" page
  • Cessation of collection/processing/use: you can request cessation of data processing through the "Delete Account" function
  • Deletion: you can request account deletion; the system will anonymize your personal data

To exercise the above rights, please contact: cs@unitop.com.tw

VI. Data Retention Period
  • Order records (including ticket numbers, amounts, flight information): retained for 7 years in compliance with the Commercial Accounting Act
  • Passenger passport and ARC numbers: automatically deleted 180 days after travel departure and immediately anonymized upon account deletion
  • OCR recognition raw text: automatically anonymized after 90 days
  • Order GDS raw data (PNR RAW): deleted 180 days after order completion or cancellation
  • Operation logs: automatically deleted after 2 years of retention
  • Account data: retained during account existence and immediately anonymized upon account deletion
VII. Cookie Usage

This system uses the following cookies:

  • Session Cookie (MIGRANT_SESSION): maintains login status and expires when the browser is closed
  • Remember Me Cookie: set when "Remember Me" is selected, valid for 30 days
  • CSRF Token: prevents cross-site request forgery attacks
  • Language preference: records your selected interface language

This system does not use third-party tracking cookies or advertising cookies.

VIII. Contact Information

If you have any questions about this privacy policy, please contact:

Return to Home