Privacy Policy
Last updated: 2026-05-07 · Effective: 2026-05-07
This Privacy Policy describes how MiGo Piggy (the "App", "we", "us", "our") collects, uses, discloses, and protects your personal information. We comply with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
1. Who we are
MiGo Piggy is operated by an individual app developer (sole-proprietor capacity) based in Sydney, Australia, at the address listed in section 12. For the purposes of the Australian Privacy Act 1988 (Cth), we are the entity responsible for handling your personal information.
2. What information we collect
We collect only what we need to operate the service:
- Account information. Your email address (when you sign up via email OTP) or your Apple user identifier (when you sign in with Apple). Apple does not share your real Apple ID email with us unless you choose to.
- Phone number (optional). Only required when you write a review or claim a merchant listing — for spam and fraud prevention. Verified via SMS OTP.
- Authentication metadata. IP address, user agent, device identifier, and timestamps — used to rate-limit OTP requests and detect abuse. Retained for 30 days.
- Location (only while using the app). If you grant location permission, we use your coarse location to find nearby merchants. We do not track your location in the background. You can revoke this permission anytime in iOS Settings.
- User-generated content. Reviews, ratings, favorites, and any photos you choose to upload.
- Merchant subscription data (merchants only). If you claim a merchant listing and subscribe, Stripe handles your payment data — we never see your card number. We retain only the subscription status and Stripe customer reference.
- Diagnostic data. Crash reports and error stack traces, sent to Sentry. We make best efforts to scrub personal information from these, but they may include device model, OS version, and app version.
- Cookies and local storage. The app stores a JWT session token on your device so you stay signed in. Our marketing site (this page) uses no third-party trackers.
We do not collect: contacts, photos library (we only access photos you actively pick), microphone, camera (unless you upload a photo), HealthKit, calendar, or any other sensitive iOS data class.
3. How we use your information
- Operate the service: search, listings, reviews, favorites.
- Authenticate you and prevent abuse (rate-limiting OTP, blocking spam reviews).
- Send transactional emails (OTP codes, account notifications) via AWS SES.
- Send transactional SMS (OTP codes) via AWS SNS — only if you opted in to phone verification.
- Diagnose crashes and improve stability.
- Comply with legal obligations.
We do not:
- Sell your personal information to anyone.
- Use your data for third-party advertising or behavioural targeting.
- Profile you for marketing.
- Track you across other apps or websites.
4. Who we share with
We share data only with the service providers necessary to operate the App. Each is contractually obliged to handle your data responsibly:
- Amazon Web Services (AWS), region ap-southeast-2 (Sydney). Hosts our database, file storage, email, and SMS infrastructure. Your data stays within Australia.
- Apple Inc. When you use "Sign in with Apple", Apple's privacy practices apply to that authentication step.
- Stripe (merchants only). Processes merchant subscription payments. PCI-DSS Level 1 compliant.
- Sentry. Error and crash tracking. Some diagnostic data may be processed in the United States.
- Cloudflare. DNS, edge caching, and inbound email forwarding.
- MaxMind / ip-api.com (optional). IP-to-country lookup for analytics. Only your IP is sent.
We do not transfer your data to any other third party without your consent, except where required by Australian law (e.g., a court order).
5. International data transfer
Most of your data is stored in Australia (AWS Sydney region). Some service providers — Sentry, Stripe, and Apple — operate internationally and may process data in the United States or elsewhere. Where we transfer personal information overseas, we take reasonable steps to ensure the recipient handles it consistent with the APPs.
6. Security
- All traffic between your device and our servers is encrypted using TLS 1.2+.
- Our database (AWS RDS) is encrypted at rest.
- OTP codes are hashed (HMAC-SHA256) before storage; we never store plaintext OTPs.
- Server access is restricted via IAM, SSH key authentication, and VPC private subnets.
- Production systems are monitored and audited continuously.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
7. How long we keep it
- Active account data: for as long as your account is active.
- After account deletion: personal data is removed within 30 days, except records we are required to retain by Australian law (e.g., financial transaction records — typically 7 years).
- Reviews you posted: by default kept anonymised (display name removed) for community value. You may request full deletion via support@migopiggy.com.
- Diagnostic and authentication logs: 30 days.
- Email delivery logs (DMARC reports, bounces): 30 days.
8. Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or out-of-date information.
- Delete your account and associated personal information.
- Withdraw consent (note: withdrawing consent for required data, such as authentication, will make the service unusable).
- Lodge a complaint with the OAIC (oaic.gov.au) if you believe we have mishandled your data.
To exercise these rights, email support@migopiggy.com. We will respond within 5 Australian business days. We may need to verify your identity before processing the request.
Account deletion is also available in-app: Profile → Settings → Delete Account.
9. Cookies and tracking
The App stores a JWT session token in iOS secure storage so you stay signed in. This token contains your user identifier only — no other personal information.
Our marketing website (the page you are reading) uses no third-party trackers, no advertising pixels, no Google Analytics, and no social media plugins. Cloudflare, our edge provider, may log basic request metadata (IP, user agent, response status) for security and abuse prevention.
Our companion survey site (survey.migopiggy.com) collects anonymous interaction data (duration, page-by-page progress, country of origin). It does not require an account and does not link to App accounts.
10. Children
The App is intended for users aged 17 or older, consistent with the App Store age rating for apps with user-generated content and reviews. We do not knowingly collect personal information from children under 17. If you believe we have, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date above. For material changes, we will notify you in-app or by email. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
12. Contact
- Email: support@migopiggy.com
- Postal: 55 Dalmeny Avenue, Rosebery NSW 2018, Australia
- Privacy regulator: Office of the Australian Information Commissioner (OAIC), oaic.gov.au, 1300 363 992
隐私政策
最后更新:2026-05-07 · 生效日期:2026-05-07
本政策说明 MiGo Piggy("我们","App")如何收集、使用、披露和保护你的个人信息。我们遵守《澳大利亚 1988 年隐私法》(Privacy Act 1988 (Cth))及其下的 13 条澳大利亚隐私原则(APPs)。
本中文版仅为方便阅读提供。如中英文表述存在歧义,以英文版为准。
1. 我们是谁
MiGo Piggy 由一名个人开发者(个人独资经营)运营,办公地址位于澳大利亚悉尼,详细地址见第 12 节。在《1988 年隐私法》下,我们是负责处理你个人信息的主体。
2. 我们收集什么
- 账号信息:邮箱(用邮箱 OTP 注册时)或 Apple 用户标识(用"通过 Apple 登录"时)。如果你选择隐藏邮箱,Apple 不会把你真实邮箱给我们。
- 手机号(可选):只有当你写评价或认领商家时才需要,用于反垃圾和防欺诈。通过短信 OTP 验证。
- 登录元数据:IP、user agent、设备标识、时间戳。用于 OTP 限流和滥用检测。保留 30 天。
- 位置(仅使用 App 期间):你授权后,我们用粗略位置查附近商家。我们不在后台跟踪你的位置。你随时可以在 iOS 设置里取消授权。
- 用户生成内容:评价、评分、收藏、你主动上传的照片。
- 商家订阅数据(仅商家):你认领商家并订阅时,Stripe 处理支付数据,我们看不到你的卡号。我们只保留订阅状态和 Stripe customer 引用。
- 诊断数据:崩溃报告和错误堆栈,发送给 Sentry。我们尽量去除其中的个人信息,但可能包含设备型号、iOS 版本、App 版本。
- Cookie 与本地存储:App 在 iOS 安全存储里保存 JWT 会话令牌让你保持登录。本营销站点不使用任何第三方追踪。
我们不收集:通讯录、相册(仅访问你主动选择上传的照片)、麦克风、摄像头(除非你上传照片)、HealthKit、日历或其他敏感 iOS 数据类。
3. 我们如何使用
- 提供服务:搜索、列表、评价、收藏。
- 身份认证和反滥用(OTP 限流、屏蔽垃圾评论)。
- 通过 AWS SES 发送事务性邮件(OTP 验证码、账号通知)。
- 通过 AWS SNS 发送事务性短信(OTP 验证码)——仅在你启用了手机验证时。
- 诊断崩溃,提升稳定性。
- 履行法律义务。
我们不会:
- 把你的个人信息卖给任何人。
- 用你的数据做第三方广告或行为定向。
- 为营销目的给你打用户画像。
- 跨 App 或网站追踪你。
4. 我们与谁分享
我们只与运营 App 必需的服务商共享数据,每一家都受合同约束负责任地处理你的数据:
- AWS(ap-southeast-2 悉尼区域):托管我们的数据库、文件、邮件、短信基础设施。数据留在澳大利亚境内。
- Apple Inc.:使用"通过 Apple 登录"时,Apple 的隐私实践适用于该认证步骤。
- Stripe(仅商家):处理商家订阅付款。PCI-DSS Level 1 合规。
- Sentry:错误与崩溃跟踪。部分诊断数据可能在美国处理。
- Cloudflare:DNS、边缘缓存、入站邮件转发。
- MaxMind / ip-api.com(可选):IP 国家归属。仅传 IP。
除非澳大利亚法律要求(如法院命令)或得到你同意,我们不会把数据传给其他任何第三方。
5. 跨境数据传输
大部分数据存放在澳大利亚(AWS 悉尼区域)。Sentry、Stripe、Apple 等服务商在国际范围运营,数据可能在美国或其他地区处理。我们已采取合理措施确保境外接收方按 APPs 合规处理你的个人信息。
6. 安全
- 客户端到服务器的全部流量使用 TLS 1.2+ 加密。
- 数据库(AWS RDS)静态加密。
- OTP 在存储前用 HMAC-SHA256 哈希;不保存明文 OTP。
- 服务器访问受 IAM、SSH 密钥、VPC 私有子网限制。
- 生产系统持续监控与审计。
如果发生可能导致严重损害的数据泄露,我们会按"强制泄露通知制度(NDB scheme)"通知受影响个人和澳大利亚信息专员办公室(OAIC)。
7. 保留期限
- 账号活跃数据:账号有效期间。
- 注销后:个人数据 30 天内删除,澳大利亚法律要求保留的(如财务交易记录通常 7 年)除外。
- 你发布的评价:默认匿名化保留(去除显示名)以服务社区。可邮件 support@migopiggy.com 申请彻底删除。
- 诊断与登录日志:30 天。
- 邮件投递日志(DMARC、bounce):30 天。
8. 你的权利
根据 APPs,你有权:
- 访问我们持有的关于你的个人信息。
- 更正不准确或过时的信息。
- 删除你的账号及相关个人信息。
- 撤回同意(注意:撤回必需数据的同意会让 App 无法使用)。
- 向 OAIC(oaic.gov.au)投诉如认为我们处理不当。
邮件 support@migopiggy.com 行使上述权利,我们在 5 个澳大利亚工作日内回复。处理前我们可能需要核验你的身份。
账号注销也可在 App 内完成:个人 → 设置 → 注销账号。
9. Cookie 与追踪
App 在 iOS 安全存储里保留 JWT 会话令牌让你保持登录。该令牌只包含你的用户 ID,无其他个人信息。
本营销网站不使用任何第三方追踪、广告像素、Google Analytics 或社交媒体插件。Cloudflare 边缘可能记录基本请求元数据(IP、user agent、响应状态)用于安全与反滥用。
我们的产品调研站点 survey.migopiggy.com 收集匿名交互数据(停留时长、逐页进度、来源国家),不需要账号,也不与 App 账号关联。
10. 未成年人
本 App 面向 17 岁及以上用户,与 App Store 对含用户生成内容与评价的应用的年龄分级一致。我们不会有意收集 17 岁以下用户的个人信息。如果你认为我们收集了,请联系我们,我们会及时删除。
11. 政策变更
我们可能会不时更新本政策。更新后版本会发布在本页并修改顶部的"最后更新"日期。重大变更会在 App 内或通过邮件通知你。变更生效后继续使用 App 即视为同意更新后政策。
12. 联系我们
- 邮箱:support@migopiggy.com
- 邮寄地址:55 Dalmeny Avenue, Rosebery NSW 2018, Australia
- 隐私监管机构:澳大利亚信息专员办公室(OAIC),oaic.gov.au,1300 363 992