Privacy Policy
Last updated: July 16, 2026
This policy explains what Toyoni collects, why, who we share it with, and your rights.
1. What we collect
- Site analytics. We use PostHog for aggregate product analytics and Microsoft Clarity for behavioral metrics, heatmaps, and session replay. These services can receive page paths, clicks, scrolling and pointer activity, browser/device details, language, and approximate location derived from IP. Clarity receives only coarse custom tags for locale and page type; we do not send it names, email addresses, phone numbers, task details, message content, or payment data.
- Messages you send. When you contact us on WhatsApp, KakaoTalk, LINE, Instagram, or Messenger, that platform handles the message under its own policy; we receive what you send (including screenshots) to do the task.
- Task details. Information you give us to complete a request — which may include your name, passport/ID details, delivery address, and booking info. We use these only to perform the task you asked for.
- Payments. Processed by Stripe. We do not store full card numbers; we keep a record of the amount, status, and a reference to your request.
- Operational records. A request ledger (status: quoted, paid, completed) we keep to run the service.
2. Why we use it (legal bases)
- To perform your task (contract) — task details, payment.
- To run and improve the service (legitimate interests) — operational records, aggregate analytics.
- Analytics cookies and session continuity (consent) — where required, only after you opt in.
3. Sensitive details (ID, passport)
If a task requires identity details, we collect only what’s needed, use them solely to complete that task, transmit them through the relevant platform, and don’t keep them longer than necessary. We never sell personal data.
4. Who we share with
Only as needed to provide the service: the third-party platform/merchant for your task (e.g. a ticketing site), Stripe (payments), PostHog (product analytics), Microsoft Clarity (behavioral analytics and session replay), Google (our operational sheet), and the chat platform you contacted us on. These providers process data under their own terms and applicable data-protection roles. We don’t sell your data or use Clarity data for third-party advertising. See the Microsoft Privacy Statement for Microsoft’s data practices.
5. Cookies & consent
Essential functionality uses minimal local storage. Visitors in the EU/EEA, UK, Switzerland, and Brazil are shown an analytics consent banner. PostHog is not loaded in these regions unless analytics is accepted. Elsewhere it may load after the geo check records an implied analytics state, as permitted by applicable law.
Clarity always receives advertising storage as denied. Before analytics is accepted in a consent-gated region, Clarity receives analytics storage as denied: it does not set its first- or third-party cookies, but Microsoft may collect limited cookieless page-interaction data with each page view treated separately. If analytics is accepted, Clarity may set cookies that connect page views into a session and enable full heatmaps and replay. If consent is declined after cookies existed, Clarity’s Consent V2 signal instructs it to delete its cookies and return to cookieless mode.
We do not run Clarity on the personalized welcome/chat-composer flow. On other pages, entire forms, editable regions, and galleries containing real chat screenshots are explicitly masked before Clarity capture; Clarity also masks input and dropdown content. Clearing Toyoni’s local storage removes the saved choice, so the site will ask again when consent is required.
6. Retention
We keep task and payment records as long as needed for the service, accounting, and legal obligations, then delete or anonymize them. Analytics data is retained under our PostHog configuration and Microsoft Clarity’s published retention periods. Clarity playback data is generally retained for 30 days; aggregate click/heatmap data and sessions selected for longer-term review may be retained longer under Microsoft’s current policy.
7. Your rights
Depending on where you live (e.g. GDPR/UK-GDPR, Korea PIPA, Brazil LGPD) you may have rights to access, correct, delete, or port your data, and to object to or restrict processing. To exercise them, contact us (below). You can also complain to your local data protection authority.
8. International transfers
We operate from Korea and use global processors, so data may be processed outside your country. Where required, transfers rely on appropriate safeguards.
9. Security
We use reasonable technical and organizational measures to protect your data. No method is perfectly secure, but we limit who can access task details and don’t store payment card numbers.
10. Children
Toyoni isn’t intended for anyone under 18.
11. Changes & contact
We’ll post updates here with a new date. Questions or requests: message us in any of our chat channels.
