Vtuber-Site
Vtuber-Site
  • Notifications
    No notifications
    • Terms and Conditions
    • Privacy Policy
    • Notifications
      No notifications
    • Current language English
      • English English
      • Traditional Chinese Traditional Chinese
      • Simplified Chinese Simplified Chinese
    • Login
    • Register
      • Seller Register

    Privacy Policy

    Privacy Policy

    Last Updated: 2026-08-12

    Scope of this Privacy Policy

    This Privacy Policy describes the information handled by this website and its authenticated seller and administration areas. The public Privacy Policy page is available without signing in.

    Operator and Privacy Contact

    This website is operated under the name Vtuber Site. It is an online service and does not maintain a physical business address. For privacy questions, access or correction requests, deletion requests, or other data concerns, contact [email protected].

    Information Collected When You Register

    Account registration requires your name, email address, and password. The application stores the password as a hash rather than as plain text. User records also contain an account type, role, active status, and email verification timestamp.

    Seller Information

    Seller registration may collect a selected plan, business type, channel name, YouTube username, X username or identifier, Bluesky identifier, tags, website title, location, and currency. Seller profiles can also contain storefront settings, social-media identifiers, synchronisation settings, and payment configuration.

    Orders, Checkout, and Support

    When you use shopping features, the application can store cart items, product selections, quantities, prices, order details, billing and shipping addresses, phone number, email address, remarks, and order status. Sellers and administrators can also process support tickets and related notifications.

    Uploaded Images and Published Content

    Seller and administrator upload features accept image files and store the original file name, generated file name, file size, extension, type, and image dimensions. Uploaded files are stored by the application and may be displayed by the website. The current upload validation limits each file to 15 MB and permits configured image and cursor formats.

    Google and YouTube Connection

    If a seller connects Google, the application requests OpenID, email, profile, and read-only YouTube access. It uses the connection to obtain the Google subject identifier and YouTube channel information, then stores the local OAuth connection, channel identifier, and YouTube username. Disconnecting Google clears the stored local Google OAuth connection and YouTube connection fields.

    X Connection

    If a seller connects X, the application obtains the X user identifier and username through its OAuth flow, stores the local OAuth connection and seller X identifier, and can use the connection for the seller features implemented by the application. Disconnecting X clears the stored local X OAuth connection and seller X identifier.

    Notifications and External Services

    The application uses email for account and support notifications. Depending on the configured features, it can send administrator or seller notifications through Telegram and Discord. It also uses Google services for OAuth, reCAPTCHA, and YouTube requests; X for OAuth requests; Stripe for checkout and payment verification; and Discord for bot features. Each provider may process information under its own terms and privacy policy.

    Cookies, Sessions, and Technical Records

    The application uses a session cookie and server-side session data to authenticate users, preserve form and OAuth state, and maintain signed-in sessions. The configured defaults use database sessions, encrypted session data, HTTP-only cookies, SameSite Lax cookies, and a 120-minute idle lifetime; deployment environment settings may change these defaults. The application also records request and account information needed for invitations, auditing, security, and service operation.

    The website also stores a locale preference cookie for up to one year. Browser local storage remembers the selected theme and the time when the Cookie Notice was acknowledged; the acknowledgement remains valid for up to one year before the notice is shown again.

    These cookies and browser storage are used for essential security, account, language, and preference features. The current application does not install analytics or advertising cookies. Clicking Got it records that the notice was acknowledged; it does not enable optional tracking.

    Connected providers, including Google reCAPTCHA, Google and YouTube, X, Stripe, and Discord, may use their own cookies or browser storage when their services are loaded or used, subject to their own privacy policies. You can clear or block cookies and browser storage in your browser settings, but account, security, language, and preference features may stop working correctly.

    Purposes of Use

    The information described above is used to create and authenticate accounts, operate seller storefronts, synchronise connected social-media data, display published content, process carts and orders, verify Stripe payments, provide support, send service notifications, enforce permissions, protect the application, and maintain audit and operational records.

    Retention and Deletion

    The source code does not define one fixed retention period for all account, order, upload, OAuth, notification, or audit records. Some records are soft-deleted, while disconnect actions remove the local Google or X connection records and related seller connection fields. Do not treat disconnecting an account as a request to erase every related record or as revocation of a provider authorization.

    Data Access and Correction Requests

    The current application does not expose a public self-service data export or deletion endpoint. Requests to access or correct personal data therefore require an operator-controlled contact process to be provided and maintained outside the routes currently present in this project.

    Seller Region Privacy Law

    Where a seller relationship or transaction is involved, this policy should be read together with the privacy laws applicable to the seller region recorded in the relevant seller profile. The application permits HK, TW, JP, and US as seller location values and does not implement a separate privacy regime or legal jurisdiction selector. The operator should review and update this policy, its retention practice, its data access process, and its provider contracts before production publication.

    Vtuber-Site
    Quick Links
    • Home
    • Privacy Policy
    • Terms and Conditions
    Contact Us

    Not set


    © 2026 Vtuber-Site. All rights reserved.

    Cookie Notice

    We use essential cookies to keep this website secure and working correctly. Please review our Privacy Policy and our Terms and Conditions.