LEGAL · PRIVACY POLICY
Lava Privacy Policy
Last updated 2026-09-17 · Effective 2026-09-17
Contents
- Summary
- 1. Scope and data controller
- 2. What personal data we collect
- 3. How we handle sensitive personal data
- 4. Why we collect and use your data
- 5. Period, region, recipients, and method of use
- 6. What we share with partner venues and your date
- 7. How long we keep your data
- 8. Your rights and how to exercise them
- 9. Cookies and App SDKs
- 10. Minors
- 11. Data security measures
- 12. Data breach notification
- 13. Changes to this policy
- 14. How to contact us
- Contact us
- Revision history
Summary
- Your personal data is managed by Lava Intelligence Co., Ltd.
- Email or phone number, date of birth, and photos are required. Everything else is optional.
- Your human verification selfie is used only to confirm you are a real person, and it is reviewed by our staff.
- Location can be live location or a fixed city. You can turn it off at any time.
- We do not store your full card number. Payments are handled by the payment system we engage.
- Your date cannot see your phone number or email.
- Most of the cloud services we use are hosted outside Taiwan.
- After you delete your account, we delete or de-identify your data within 30 days.
1. Scope and data controller
1. Who manages your data
The data controller for this policy, which is a non-government agency as defined in the Taiwan Personal Data Protection Act (PDPA), is:
- Name: Lava Intelligence Co., Ltd. ("the Company" or "we")
- Unified Business Number (tax ID): 60687346
- Business address: 3F, No. 129, Sec. 3, Chongqing S. Rd., Zhongzheng Dist., Taipei City, Taiwan
- Personal data contact: service@lava.tw (put "Personal data" in the subject line)
2. What this policy covers
This policy applies to the following services provided by the Company (together, "the Service"):
- The Lava App (iOS and Android), including sign-up, human verification, matching, chat, date invitations, payments, and event registration.
- The official website, lava.tw.
- Our customer support inbox and other contact channels the Company provides.
This policy explains how we collect, process, use, and protect your personal data, and the rights you have under the PDPA. This policy is part of the Lava Terms of Service. Please read it in full before you use the Service.
3. Who the Service is for
The Service is intended for users in Taiwan who are 18 or older. If you are in the EU or the UK, you have additional rights under local law beyond those described in this policy. You can exercise them through the channels in Section 14.
2. What personal data we collect
The table below lists the categories of data we collect, where it comes from, whether it is required to use the Service, and what happens if you do not provide it.
| Category | Fields | Source | Required? | If you do not provide it |
|---|---|---|---|---|
| Account and identity | Email or phone number, verification code; platform ID, email, and name provided by social login (Apple, Google, Facebook, LINE); nickname, date of birth, gender | You; social login platforms | Required | You cannot create an account |
| Profile | Photos, bio, school, company, gender of people you want to meet, sign-up Q&A, custom questions and answers | You | Photos and the gender of people you want to meet are required; the rest is optional | Without photos you cannot unlock matching; leaving optional fields blank only affects recommendation quality |
| Human verification images | Selfie images taken as instructed in the App, review result, reason for rejection | You; reviewed by Company staff | Required for matching and some features | You cannot use matching or some features |
| Location | Live location coordinates (when enabled), current city or county, city derived from reverse geocoding of your coordinates | Device location (with your permission); the city you choose | Live location or a fixed city, one or the other | If you do not enable live location, you can use a fixed city instead; without either, we cannot recommend people to you |
| Booking contact | Name, phone number, and email you enter when sending or accepting a date invitation | You | Required when a date is confirmed | You cannot complete the date booking |
| Payments and transactions | Order number, amount, payment and refund status, Lava Point records, SuperLike purchase and usage records, event registration plan, e-invoice carrier. Card data (first six and last four digits of the card number, issuing bank, expiry month and year, cardholder name) is received and stored by the third-party payment service we engage. The Company does not store full card numbers | You; returned by the third-party payment service | Required for paid features | You cannot pay |
| Interactions and activity | Discover history (likes, passes, SuperLikes, time spent viewing), blocks and reports, chat messages (text and GIFs), quick-question answers, attendance confirmation, cancellation reasons and notes, check-in scan time, post-date survey, impressions and taps on in-App event placements | Generated when you use the Service | Generated automatically when you use the related features | Not generated if you do not use the feature |
| Device and push notifications | Device name, model, operating system version, platform, push token, last active time, login session, and user agent | Provided automatically by your device | Push token is optional | Turning off push notifications only means you will not receive notifications |
| Support and notifications | Support correspondence, notification delivery records, notification preferences | You; generated by our systems | Required when you contact support | We cannot handle your request |
| Error and performance logs | Request information at the time of an error, including IP address, device and App version, account ID | Generated automatically by our systems | Generated automatically | None |
A few more things to note:
- We analyze your bio, school, company, Q&A content, and profile photos by automated means for matching recommendations (see Section 4).
- Apart from error and performance logs, we do not write your IP address to our database.
- The App does not use advertising identifiers (IDFA, GAID) and does not track you across apps.
3. How we handle sensitive personal data
Article 6 of the PDPA classifies medical records, medical treatment, genetic data, sex life, health checks, and criminal records as sensitive personal data, which in principle may not be collected. Here is how we handle it.
1. Gender of people you want to meet
The "gender of people you want to meet" field in your profile may be treated as sexual orientation data, which falls under sex life as a category of sensitive personal data. We collect it only after you give consent in a separate step in the App, and we keep the consent record as an electronic document.
- Purpose: used only to decide which people we recommend to you and to whom we recommend you.
- Scope: not disclosed externally, not used for marketing, and not shared with partner venues.
- Withdrawal: you can change this field in your profile at any time, or email us to ask us to stop using it. This field is required for matching recommendations. If you withdraw it, matching will no longer work.
2. Human verification images
The selfie you take for human verification is a facial image that can identify you. Here is how we handle it:
- Purpose: to confirm there is a real person behind the account, and to prevent fake accounts and impersonation.
- Method: Company staff compare your selfie with your profile photos. We do not currently use automated facial recognition.
- Disclosure: not shown to other users. Only authorized reviewers can view it.
- Retention: see the retention table in Section 7.
Human verification only confirms that you are a real person. We do not check government ID, criminal records, or marital status.
3. Data we do not collect
- Criminal records: the "no criminal record" statement at sign-up is your own declaration. We do not verify it with any authority, and we do not collect criminal records.
- Medical records, medical treatment, genetic data, and health check data: we do not actively collect these. If you mention them in your bio or in chat, that content is shown to the other person according to your settings. Please use your own judgment.
4. Why we collect and use your data
We collect and use your personal data for the purposes below. The numbers in parentheses are the specific purpose codes published by the Taiwan Ministry of Justice.
1. Providing the Service (performance of contract)
- Creating and managing accounts, verifying identity, human verification (069 Contracts, quasi-contracts, or other legal relationships; 090 Consumer and customer management and service).
- Matching recommendations, chat, date invitations, time slot and venue arrangements, check-in, event registration (069; 135 Information and communication services).
- Collecting matching service fees, SuperLike fees, and event fees; handling refunds, Lava Point, and e-invoices (069; 148 Online shopping and other e-commerce services).
- Sending service-related notifications: verification codes, payment confirmations, venue confirmations, attendance reminders, cancellation notices (069).
- Customer support, complaints, and dispute handling (090).
2. Safety and abuse prevention (performance of contract and legitimate business)
- Detecting fake accounts, fraud, harassment, and violations of the community guidelines, and handling reports and blocks (069; 181 Other business operations in accordance with the business registration or articles of incorporation).
- Preserving evidence as required by law and cooperating with lawful investigations by judicial and police authorities (063 Collection, processing, and use of personal data by non-government agencies under legal obligations).
3. Service improvement and statistics (legitimate business)
- Error tracking and performance monitoring (136 Information, communication, and database management).
- Statistical analysis of usage to improve the product (157 Surveys, statistics, and research analysis).
4. Marketing (with your consent)
- Notifying you of events, promotions, and new features through App push notifications (040 Marketing).
- You can turn off marketing push notifications in the App's notification settings. The first marketing message will include how to opt out. Once you opt out, we stop immediately.
5. Matching recommendations and automated processing
Matching recommendations are ranked automatically by our system based on the following data:
- Your preferences: gender of people you want to meet, distance range, age range.
- Your location and the other person's location (live location or fixed city).
- Your interaction history: likes, passes, SuperLikes, blocks.
- Profile similarity: the Company analyzes your profile content by automated means to assess how similar you are to other users.
- Whether the other person has completed human verification (used for the verification badge and push notification filtering).
The following processing produces automated outcomes that affect you:
- Suspension: when our systems detect multiple open reports against your account, or profile content that violates the community guidelines, the system may suspend your account automatically.
- Attendance and refunds: the system determines your attendance status and calculates refunds automatically based on your attendance confirmation in the App and your check-in scan time. The rules are set out in the Lava Terms of Service.
You can appeal an automated suspension or automated determination by emailing service@lava.tw. Company staff will review it and reply.
6. Use for other purposes
We use your personal data only as necessary for the purposes above. If we need to use it for another purpose, we will tell you the purpose, scope, and impact, and obtain your separate consent.
5. Period, region, recipients, and method of use
1. Period
See the retention table in Section 7.
2. Region
Taiwan, and the countries or regions where the service providers we engage are located. Most of the cloud services we use are hosted outside Taiwan. Your photos, verification images, error logs, AI analysis content, and push notification content are all transferred abroad for processing.
3. Recipients
- The Company and its authorized staff.
- The service providers we engage, listed by category in Section 5.5 below.
- Partner venues and your date, within the scope described in Section 6.
- Judicial, police, and other legally authorized authorities, when required by law.
- The successor in a merger, spin-off, or business transfer involving the Company. We will notify you before the transfer and require the successor to protect your data under this policy.
4. Method
Automated and non-automated collection, processing, and use by electronic means, including storage, transmission, comparison, analysis, and deletion.
5. Categories of service providers we engage
We engage service providers in the following categories to process your personal data. Our contracts require them to process data only on the Company's instructions, take security measures, and delete or return the data when the engagement ends.
| Category | Purpose | Data shared | Processing region |
|---|---|---|---|
| Social login services | Verify identity and create your account | Platform ID, email, and name provided by the social login platform you choose | Outside Taiwan |
| SMS delivery services | Send phone verification codes | Phone number | Outside Taiwan |
| Email delivery services | Verification codes, payment confirmations, venue notices, cancellation notices | Email, notification content | Outside Taiwan |
| Push notification services | App push notifications | Push token, notification content | Outside Taiwan |
| Cloud file storage services | Store profile photos and human verification images | Photos, verification images | Outside Taiwan |
| System error monitoring services | Error and performance monitoring | Request information at the time of an error, including IP address, device information, account ID | Outside Taiwan |
| Usage analytics services | Usage statistics | Event records, including account ID, date ID, order amount | Outside Taiwan |
| Geographic information services | Convert coordinates to city or county | Latitude and longitude | Outside Taiwan |
| AI content analysis services | Analyze profile content to support matching recommendations; generate quick questions | Bio, school, company, Q&A content, profile photos | Outside Taiwan |
| Payment and e-invoicing services | Create member records, payments, refunds, Lava Point, issue e-invoices | Email, name, card data, order details | In Taiwan |
| Customer service and operations management tools | Handle support cases and confirm attendance at dates | Name, phone number, email, date and order details, attendance and payment status | Outside Taiwan |
AI content analysis services are used through their interfaces. Under the commercial terms the Company has signed with those providers, your data is not used to train their public models.
6. Cross-border transfer notice
Your personal data is transferred outside Taiwan for processing. The purposes are providing the Service, maintaining security, and improving the Service. We supervise our processors under Article 8 of the Enforcement Rules of the PDPA and require by contract that they take protective measures no weaker than those under the PDPA. We do not transfer your personal data to mainland China for processing.
7. What we do not do
- We do not sell your personal data.
- We do not give your personal data to advertisers for cross-site or cross-app tracking.
- We do not proactively give your data to any government agency unless required by law.
6. What we share with partner venues and your date
1. What your date can see
After you match, the other person can see:
- Your profile: nickname, photos, age, bio, school, company, Q&A content, human verification badge.
- The chat messages between you, and your answers to quick questions and custom questions.
- Once a date is confirmed: the date, time slot, partner venue, and your attendance status.
- If you indicate after attendance confirmation that you will not attend, the reason and note you enter are shown to the other person.
The other person cannot see your phone number, email, booking name, or payment data.
2. What partner venues receive
Once a date is confirmed, the Company keeps the date, time, venue, both parties' order numbers, booking names, phone numbers, emails, and attendance status, which we use to book with the partner venue and confirm check-in. The partner venue receives only what it needs for the booking: booking name, party size, and time slot, plus a contact phone number when needed. The partner venue does not receive your profile, chat content, or payment data.
3. Check-in scan
Thirty minutes before the date starts, the App unlocks a check-in QR code. When you scan the QR code at the partner venue, the system records the scan time, which is used to determine attendance and calculate refunds. You complete the scan in the App. The partner venue does not receive your account data through the scan.
4. Events
When you register for an event hosted by the Company, members of your group can see your nickname and profile. The event venue receives only the party size and time slot.
7. How long we keep your data
| Data category | Retention period | Notes |
|---|---|---|
| Account and profile | While your account is active; deleted or de-identified within 30 days after account deletion | Except where the law requires retention |
| Human verification images and review results | While your account is active; deleted within 30 days after account deletion | Used to prevent repeat verification and handle review disputes |
| Gender of people you want to meet | While your account is active; updated as soon as you change or delete it | We stop using it once you withdraw consent |
| Location | Live location coordinates and city records are kept until account deletion | We may periodically aggregate coordinates to the city level and delete the raw coordinates |
| Chat messages and interaction records | While your account is active; deleted within 30 days after account deletion | Copies of conversations in the other person's account are handled according to that account's status |
| Booking contact details | 1 year after the date ends | Used to handle refunds and disputes |
| Payment and transaction records, e-invoices | At least 5 years from completion of the transaction | Retained under the Business Entity Accounting Act and tax law |
| Lava Point and SuperLike records | While your account is active; after account deletion, kept for the same period as transaction records | Stored by the third-party payment service we engage |
| Report, block, and suspension records | 3 years after the case is closed | Used to prevent abuse and handle disputes |
| Support correspondence | 3 years after the case is closed | |
| Names and phone numbers in support and booking records | 1 year after the date ends | |
| Device data and push tokens | Deleted immediately when you delete your account | Login sessions expire after a set period |
| Error and performance logs | Up to 90 days | |
| Product analytics events | Up to 1 year | |
| Account deletion records (the email or phone number used to sign up, deletion time) | 2 years after deletion | Used to prevent abuse and handle disputes |
| Consent records (policy version, time of consent) | 5 years after account deletion | To meet our burden of proof under Article 7 of the PDPA |
Legal exceptions:
- When we receive a notice from the competent authority or the police under the Sexual Assault Crime Prevention Act or the Child and Youth Sexual Exploitation Prevention Act, we keep the relevant content, account data, and usage records for 180 days, and we may not delete them on request during that period.
- While litigation, an investigation, or a dispute is ongoing, we keep the relevant data until the proceedings end.
8. Your rights and how to exercise them
1. Your rights
Under Article 3 of the PDPA, you may, with respect to your personal data:
- Inquire about it or request access to it.
- Request a copy.
- Request that it be supplemented or corrected.
- Request that we stop collecting, processing, or using it.
- Request that it be deleted.
These rights cannot be waived in advance or limited by any special agreement.
2. How to exercise them
- In the App: edit or delete your data in your profile; turn off location, push notifications, and marketing notifications in Settings; choose "Delete account" in Settings.
- By email: write to service@lava.tw with "Personal data rights request" in the subject line, and tell us which right you want to exercise and your account details. To protect your data, we will verify your identity first.
3. Response times
- Inquiry, access, and copies: we respond within 15 days of receiving your request. Where necessary, we may extend this by 15 days and will notify you in writing of the reason.
- Supplementing, correcting, stopping, and deleting: we respond within 30 days of receiving your request. Where necessary, we may extend this by 30 days and will notify you in writing of the reason.
- We may charge a fee to cover the necessary cost of providing a copy. We will tell you the fee before we proceed.
4. Exceptions
In the following situations, we may refuse all or part of a request and will explain why:
- Data we are required by law to keep, such as transaction and invoice records.
- Data needed for an ongoing report investigation, litigation, or dispute.
- Data needed to run the Service. For example, if we stop using the gender of people you want to meet, matching cannot work.
5. Withdrawing consent
You can withdraw your consent to location, marketing notifications, and the gender of people you want to meet at any time. Withdrawal does not affect processing that was lawful before you withdrew. After withdrawal, the related features may no longer be available.
6. Complaints
If you believe our processing violates the PDPA, you can complain to the Company's contact point first, and you can also file a complaint with the competent authority.
7. EU and UK users
If you are in the EU or the UK, you also have rights under local law, including data portability, the right to object to processing, and the right to complain to your local supervisory authority. You can exercise them through the same channels.
9. Cookies and App SDKs
1. Official website
The official website, lava.tw, uses only one essential cookie, "NEXT_LOCALE", to remember your language choice (Traditional Chinese or English). It expires when you close your browser. The website does not use analytics tools, advertising cookies, or any third-party tracking. If we add analytics tools in the future, we will update the Cookie Policy and provide a way to opt out.
2. SDKs in the App
The App includes third-party software packages in the following categories. Their purposes and data scope are described in Section 5.5:
- Error and performance monitoring.
- Usage statistics.
- Push notifications.
You can turn off push notification permission in your device settings. Error logs and usage statistics are necessary to provide the Service and cannot be turned off individually. You can delete your account to stop generating them.
See the Company's Cookie Policy for details.
10. Minors
The Service is only for people 18 or older. At sign-up, we confirm your age using the date of birth you enter. If we find that a user is under 18, we will terminate the account immediately and delete their personal data, except where the law requires retention. If you become aware of a minor using the Service, please email service@lava.tw or use the report feature in the App.
11. Data security measures
We take the following measures to protect your personal data:
- Encryption in transit: all transfers between the App and our servers, and between the Company and third-party processors, use TLS encryption.
- Access control: access is granted based on job role. Only authorized reviewers can view human verification images. Staff are bound by confidentiality obligations.
- Signed upload URLs: photos and verification images are uploaded through time-limited signed URLs, and the links expire after a short period.
- Login controls: login sessions and verification codes both have expiry times and stop working once they expire.
- No card data on our systems: full card numbers are handled by the payment system we engage. The Company does not store them.
- Processor oversight: we require third-party processors by contract to take security measures, and we check on this regularly.
No system can guarantee absolute security. Please keep your login details safe, and let us know immediately if you notice anything unusual.
12. Data breach notification
If your personal data is stolen, leaked, altered, or otherwise compromised, we will investigate the facts once we become aware of it. We will notify you by App notification, email, or public notice of what happened, the possible impact, and the measures we have taken, and we will report to the competent authority as required by law.
13. Changes to this policy
We may revise this policy when the law, the Service, or our processing practices change.
- Material changes: we will notify you by App notification or public notice at least 7 days before they take effect, and mark the effective date on this page.
- Minor changes: we will update this page and mark the date.
- If you do not agree with a change, you can stop using the Service and delete your account. Amounts you have already paid are handled under the Lava Terms of Service.
Previous versions are listed in the revision history at the end of this page.
14. How to contact us
If you have any questions about this policy or your personal data, contact us through:
- Email: service@lava.tw
- Mail: Lava Intelligence Co., Ltd., 3F, No. 129, Sec. 3, Chongqing S. Rd., Zhongzheng Dist., Taipei City, Taiwan
- For personal data rights requests, put "Personal data rights request" in the subject line.
Contact us
- Lava Intelligence Co., Ltd.
- Unified Business Number 60687346
- 3F, No. 129, Sec. 3, Chongqing S. Rd., Zhongzheng Dist., Taipei City, Taiwan
- service@lava.tw
Revision history
| Version date | Changes |
|---|---|
| 2025-05-29 | First version published. |
| 2026-09-17 | Full rewrite. Added a data category table, a dedicated section on sensitive personal data, an explanation of matching recommendations and automated processing, the categories of service providers we engage and a cross-border transfer notice, the scope of sharing with partner venues and dates, and a retention table by category. Adjusted response times for rights requests and how we notify you of policy changes. Security measures now list only the measures actually in place. EU and UK users now have rights under local law. |