Privacy Notice — United States
Initial public-service documents. The terms apply when a new service user accepts them. Publication itself does not establish acceptance or activate a feature.
How the Korean operator handles account information, advertising events and U.S. gift card orders.
1. Information and purposes
Account information includes social-login identifiers, email and display name, or email-registration information, a password hash, verification status and verification/reset-token checks. We use it to create, secure and recover accounts; we do not store the password in plain text.
Advertising data includes impressions, clicks, visible time, ad/campaign/client IDs, time, version, display context, authentication/deduplication data, and selected region/language. It supports billing, rewards, fraud prevention and the interface. Hosting infrastructure may process IP addresses and request logs for security and reliability.
Redemption data includes name, email, phone number where needed, country, residence/tax eligibility information, verification result/reference, reward ledger, order details and supplier status. The standard gift-card profile does not request or collect a new passport number, including for non-residents. If applicable law requires additional tax information, we separately identify the necessary items, legal basis and retention and obtain any required consent before fulfillment. New SodaGift LINK requests send the recipient's name, product, amount and order reference. We do not register an overseas bank account for a U.S. cash-out feature.
We process support messages and email recipients, subject lines, message contents and necessary verification/reset/delivery links. Optional launch alerts use email, language and consent/confirmation records. Interest/job-profile personalization is currently inactive; a new purpose or optional feature requires prior notice and consent where required.
2. Local processing and contents we do not receive
Supported-site detection, generation status, panel visibility and device activity are processed locally to derive ad events. Your conversations, source-code contents and prompt text are not sent to our servers. This does not mean that only an ad identifier and timestamp are processed.
3. Service providers and international processing
The business in the footer is the controller/operator in South Korea. Our main account, advertising and transaction database uses Supabase in Seoul; API servers use Google Cloud Platform in Seoul. The table describes external hosting, email and security services and their locations and retention criteria.
International processing and storage needed for web hosting, login, email verification and password resets rely on the contract-necessity route in Article 28-8(1)(3)(a) of Korea's Personal Information Protection Act. This basis does not cover optional launch alerts, marketing messages or a provider's independent service-improvement processing.
When you request a web page, Vercel processes your IP address, request information and necessary access logs over encrypted connections. When an authentication or reset email is requested, or a necessary service message arises, sender and recipient addresses, subject, content and required links are sent to Resend in the United States over encrypted SMTP.
You may ask the privacy contact in the footer to stop processing or close your account. Stopping hosting processing prevents use of the website; stopping authentication or reset emails prevents those email functions. Optional alerts can be withdrawn separately through their withdrawal link or our contact.
Where enabled, Cloudflare Turnstile processes browser/network signals and verification tokens for bot prevention. Identity verification uses the provider identified on the verification screen through the PortOne integration. SodaGift processes gift-card order information. If you follow a supplier's recipient link, that supplier's notice applies to information it collects directly on its site.
We do not send individual member lists, conversation contents or source-code contents to advertisers. We use information needed for each provider's function and may disclose it when required by law. New gift-card or payment features include the relevant recipient, countries, data, timing and method, purpose, retention, basis and refusal choices, with separate consent where required. Accepting general terms alone does not replace legally required transfer consent.
| Service and contact | Purpose and principal data | Location and scope |
|---|---|---|
| Supabase Pte. Ltd. (Supabase) · privacy@supabase.io | Account, advertising and transaction database | The primary database is in Seoul, Korea (ap-northeast-2). Data is kept during service use and handled under deletion requests and contractual deletion procedures. |
| Google Cloud Platform | API, security and transaction processing | API servers run in Seoul, Korea (asia-northeast3). Separate global log buckets retain default logs for 30 days and required logs for 400 days. |
| Vercel Inc. · privacy@vercel.com | Web hosting, requests and access logs | Primary facilities are in the U.S.; processing also occurs where Vercel and its subprocessors operate. Customer data can be deleted during service use and is deleted within a reasonable time after contract termination, subject to legal retention. |
| Resend (Plus Five Five, Inc.) · privacy@resend.com | Email sender/recipient addresses, subject, content and required links | Stored in the United States. Standard Free/Pro/Scale email and log retention is 30 days; a separate retention agreement takes precedence where applicable. |
| Cloudflare, Inc. (Turnstile) · dpo@cloudflare.com | Bot detection using IP/browser/connection signals and verification tokens | Cloudflare identifies the U.S. and EEA as its main storage regions, with processing across its worldwide operations. Retention follows the needs of site protection, its own bot-detection improvement and legal obligations. |
| Toss Payments Co., Ltd. | Domestic advertiser payment, cancellation, refunds and transaction identifiers | Korea; enabled payment methods only |
| Identity verification via PortOne | Name, phone and verification result through a verification reference | The actual provider and notice shown when the feature is enabled apply |
| KT alpha Co., Ltd. (Giftishow Biz) · ktalpha.help@kt.com · 1588-6474 | Korean gift-card issuance: recipient phone, product and order/transaction references | Purchase-related phone data is processed until Giftishow Biz membership withdrawal or the statutory retention period. Supplier transaction records may remain for that period after your account with us is closed. |
| SodaCrew Global Inc. (SodaGift for Business) · biz-ops@sodagift.com | LINK gift cards: recipient name, product, required amount and order reference | Processed in the U.S. and countries where affiliates or agents operate. Data is kept while needed for the account or service; deletion starts 30 days after the supplier account is deleted, with exceptions for backups, legal duties and similar needs. |
4. Retention and deletion
We keep account data while providing the service and delete eligible data after closure. Required transaction and tax records are separated and retained for the applicable legal purposes. Pending redemption or a legal obligation may require limited continued retention; we explain the relevant limits when handling a request.
Unconfirmed launch-alert requests are removed after 7 days. Confirmed requests are removed after processing the alert, except an uncertain delivery result may be checked for up to 7 days before removing the address and tokens.
Backups, security logs and provider copies follow their actual retention and deletion procedures; deletion from the active service is not a claim that every copy disappears simultaneously. The published detailed retention and transfer disclosures must match the operational settings.
Identity information collected through earlier workflows, if retained, is reviewed separately for its legal basis, continuing need and deletion. Ending new collection does not itself establish that all historical records have been deleted.
| Record | Current Korean retention policy |
|---|---|
| Cash payout records | 5 years; 국세기본법 제85조의3(장부·증빙 보존) · 전자상거래법 제6조(대금결제 기록) |
| Withholding records | 5 years; 소득세법(원천징수 지급명세서 근거 자료) |
| Transaction ledger | 5 years; 국세기본법 제85조의3(장부·증빙 보존) |
| Tax-residency determination record, excluding deleted account details | 5 years; 소득세법 제156조(비거주자 원천징수 — 거주성·국적은 세율 판단 근거 기록) |
| Gift card orders and supply | 5 years; 전자상거래법 제6조(대금결제·재화공급 기록 — 잠정 정책, 법률 검토 필요) |
5. Cookies and security
We use an encrypted session cookie that browser JavaScript cannot read, and may store language or service settings locally. Blocking cookies can prevent login. Security tools may separately process the signals explained above.
We protect sensitive payout information with encryption and restrict access to authorized personnel. Staff may access necessary information to fulfill a verified payment or support request. No transmission or storage system is an absolute security guarantee.
6. Your requests and U.S. rights
Use My personal data or the privacy contact in the footer to request access, correction, deletion, restriction or withdrawal of consent. We verify the requester using information reasonably needed to prevent unauthorized disclosure. You can ask why a request was limited and request review of that decision.
Depending on your state and whether the law applies to this business, additional rights may include obtaining a copy, opting out of sale, sharing or targeted advertising, and appealing a decision. We assess and honor rights that apply; this notice does not claim that a business-size threshold or other statutory test has already been satisfied. Exercising a right does not itself justify unlawful discrimination.
The current service does not provide individualized member profiles to advertisers or operate an interest-based advertising feature. Technical or business changes that create additional privacy choices require updated notice and controls before they begin.
7. Contact and changes
The operator's registered details and privacy officer's contact are in the footer. Contact them about handling, complaints or a privacy request. We announce notice changes and their effective date at least 7 days in advance, obtaining separate consent when required. The revision date above is not a claim that every new data transfer has begun.