Skip to main content

Privacy Policy

Last updated: April 2026

This Privacy Policy explains how Taiwan Digital Fest 2026 ("TDF 2026", "we", "us") handles personal information when you visit www.taiwandigitalfest.com/2026, buy a ticket, subscribe to our updates, or participate in festival activities. Two legal entities jointly operate TDF 2026, acting as joint controllers under Article 26 of the EU GDPR: Taiwan Digital Nomad Association (Taiwan) runs the festival, member services, and event logistics; Nomad Explore LLC (Wyoming, USA) handles ticket sales and payments. We process personal data in accordance with Taiwan's Personal Data Protection Act (PDPA), the EU General Data Protection Regulation (GDPR) where applicable, California Consumer Privacy Rights Act (CPRA), and equivalent local laws.

1. Who we are

TDF 2026 is jointly operated by two entities acting as joint data controllers:

(a) Taiwan Digital Nomad Association ("TDNA") — a non-profit society registered in Taiwan (社團法人台灣數位遊牧者協會). TDNA is the controller for festival operations, member profiles, event registrations, visa support letters, partner accommodation matching, and marketing communications. Registered address: 2F.-1, No. 72, Sec. 1, Zhongxiao W. Rd., Zhongzheng Dist., Taipei City 100, Taiwan.

(b) Nomad Explore LLC ("Nomad Explore") — a limited liability company registered in Wyoming, USA. Nomad Explore is the controller for ticket purchase transactions, including payment processing through Stripe, invoice records, and refund handling.

The two entities have signed a joint controller agreement pursuant to GDPR Article 26 that allocates responsibilities. For any privacy matter — including access, correction, deletion, portability, or consent withdrawal — you may contact either entity at fest@dna.org.tw and we will route the request to the appropriate controller on your behalf.

2. Information we collect

We collect only what is necessary to run the festival, deliver your ticket, contact you when relevant, and keep the site secure. Categories we collect:

  • Identity and contact data: name, email address, phone number, and billing/shipping address provided at checkout or newsletter signup.
  • Transaction data: ticket tier, order history, payment status, invoice numbers, refund records. Full card numbers are handled by Stripe and never stored on our servers.
  • Member profile data: display name, avatar, profile preferences, event registrations, collected namecards, and (if applicable) visa support letter requests.
  • Accommodation data: partner stay selections, invite codes, and related booking metadata when you reserve through our partner system.
  • Device and usage data: IP address, browser/OS identifiers, visitor fingerprint, referring URL, pages viewed, timestamps.
  • Analytics and marketing data: aggregated engagement metrics via Google Analytics 4 and Meta Pixel (where cookies are allowed).
  • Communications: email opens, bounces, unsubscribes, and support correspondence you send us.

3. How we use your information

We process your data only for the purposes listed below:

  • To fulfil your ticket order, issue receipts, and provide event access.
  • To send service messages (order confirmation, schedule changes, visa documents) that are required to deliver what you purchased.
  • To send newsletters, event updates, and Nomad Award announcements — only if you have subscribed or are a ticket holder and have not opted out.
  • To enable member features: namecards, event RSVP, partner accommodation booking, visa support letter generation.
  • To protect the site against fraud and abuse (rate limiting, reCAPTCHA bot filtering, visitor fingerprinting of abusive traffic).
  • To measure aggregate site performance and improve the festival (analytics).
  • To comply with legal obligations such as tax records and PDPA/GDPR requests.

4. Legal bases for processing

Where GDPR applies, we rely on the following lawful grounds: (a) performance of a contract — processing needed to deliver your ticket or member services; (b) your consent — for optional marketing emails and optional analytics cookies; (c) legitimate interests — running a safe, functional event website, preventing fraud, and measuring basic performance; (d) legal obligation — e.g. retaining financial records as required by Taiwan tax law. You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. Who we share your data with

We do not sell or share your personal information as those terms are defined in the California CPRA. We share limited data with the following processors solely so they can perform services on our behalf, and only under contractual data protection commitments:

  • Stripe, Inc. — payment processing. Stripe receives your name, email, billing address, and payment instrument. Stripe is certified PCI DSS Level 1. See stripe.com/privacy.
  • Mailgun Technologies, Inc. — transactional and marketing email delivery. Mailgun receives your email address and the content we send you.
  • Supabase Inc. — managed Postgres and authentication hosting for our application database.
  • Vercel Inc. — hosting and content delivery for the website.
  • Google LLC — reCAPTCHA Enterprise (bot protection) and Google Analytics 4 (anonymised traffic analytics).
  • Meta Platforms, Inc. — Meta Pixel (optional marketing measurement).
  • Luma (Calendar) — event RSVP and attendee list synchronisation for sessions hosted on Luma.

We may also disclose information when required by law, court order, or to protect the rights, property, or safety of TDF, our members, or the public.

6. International transfers

Some of our processors are located outside Taiwan (primarily in the United States and European Union). Where data leaves Taiwan or the EEA, we rely on standard contractual clauses or equivalent safeguards provided by the processor to protect your information.

7. How long we keep your data

We retain personal information only as long as needed for the purposes above, then delete or anonymise it. Typical retention periods:

  • Order and payment records: 5 years after the order, to meet Taiwan tax and accounting requirements.
  • Member profile and event registrations: until you delete your account or 24 months after the festival ends, whichever comes first.
  • Newsletter subscriptions: until you unsubscribe, plus a short suppression record so we don't accidentally re-contact you.
  • Email delivery logs (opens, bounces, complaints): up to 24 months for deliverability reputation.
  • Analytics data: aggregated with short identifiers, retained per Google Analytics' default retention (14 months).
  • Visitor fingerprints for abuse prevention: up to 12 months, sooner if clearly benign.

8. Your rights

Subject to local law, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion of your data where we no longer have a legal reason to keep it.
  • Export a copy of your data in a portable format.
  • Object to or restrict certain processing, including marketing.
  • Withdraw consent for optional processing at any time.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email fest@dna.org.tw. We will respond within 30 days. For email unsubscribes, every marketing email also contains a one-click unsubscribe link.

If you reside in the EU, UK, Singapore, the Philippines, Indonesia, Malaysia, Vietnam, Thailand, Japan, South Korea, or another jurisdiction with applicable data-protection law (e.g. PDPA, Personal Data Protection Act, PDPD, APPI, PIPA), you may also exercise any additional rights granted to you by that local law beyond those listed above. Send your request to fest@dna.org.tw and we will respond within 30 days or sooner if required by local law.

9. Cookies and tracking technologies

We use cookies and similar technologies for three purposes: (a) essential site functions such as authentication and cart state; (b) optional analytics (Google Analytics 4) to understand aggregate traffic; (c) optional marketing measurement (Meta Pixel) where permitted.

Essential cookies cannot be disabled. You can block analytics and marketing cookies in your browser settings or via your device's tracking-prevention features. Disabling analytics does not affect your ability to buy a ticket or use the member area.

For visitors in the EU and UK, we display a cookie consent banner and do not load optional tracking scripts until you explicitly accept.

10. Security

We protect your information using industry-standard safeguards: encrypted transport (HTTPS everywhere), encrypted database storage, access controls scoped by role, server-side secrets kept out of client code, and regular dependency security review. No system is perfectly secure, but we continuously monitor for and respond to issues.

11. Children

Our services are not directed to children under 14. We do not knowingly collect personal information from children under 14. If you believe a child has provided us with personal information, contact fest@dna.org.tw and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced on this page and, where appropriate, by email to subscribed members. The "Last updated" date at the top of the page indicates the latest revision.

Contact

Questions about this policy, or requests to exercise your rights, can be sent to fest@dna.org.tw