Privacy Policy

Last updated August 2, 2026

This translation is provided for convenience and is pending legal review. If it differs from the Korean original, the Korean version prevails.

해나랩스 complies with applicable Korean privacy law and publishes this Policy to protect user data.

1. Personal Data We Collect

Account and authentication data: email, encrypted password, organization name, and business type. Billing data: authorization and settlement details and business registration data where needed. User-entered customer, transaction, product, inventory, sales, purchase, and ledger data. External integrations the user configures: the integration login ID and login session data, stored encrypted, deleted automatically 12 hours after last use and immediately on disconnect; integration passwords are never stored. Support and bug reports: the report body, page path, app version, browser data, and any attachment. Automatically collected IP, cookies, usage records, device/browser data, and error logs.

2. Purposes

Identity and authentication; account and security management; providing, maintaining, and improving the Service; billing, settlement, tax invoices, nonpayment and abuse prevention; support, essential operational notices about the contract, fees, and outages; dispute handling and legal compliance. The Company does not send marketing messages; if it ever does, it will first obtain separate consent as required by Korea’s Network Act.

3. Personal Data the Company Processes on a User’s Behalf

For personal data of customers and other third parties that a user enters or collects through an integration (name, contact, transaction history), the personal information controller under PIPA is the user’s organization and the Company acts as its processor. Entrusted work is the storage, retrieval, modification, deletion, and backup needed to provide the Service, for the duration of the service agreement; on termination the data is destroyed or returned. The Company does not use it beyond that purpose or disclose it to third parties; details are in Article 8-2 of the Terms. Users are responsible for collecting that data lawfully and obtaining any required consent, and handle data-subject requests first, with the Company providing the necessary functions and support. Dates of birth used for age verification in integrations are processed transiently for display and order matching only and are never stored in the database.

4. Retention

Data is normally destroyed when its purpose is fulfilled or membership ends. On withdrawal, the account and that organization’s data are destroyed immediately; if a transient error leaves data behind, an automatic retry destroys it within 30 days at the latest. By Korean law, records on contracts and payments are retained for 5 years, consumer complaints for 3 years, and tax books or evidence for the statutory period. Access logs of the personal-data processing system (data-change audit records and operator action records) are kept for 1 year, the minimum required by Korea’s Personal Information Protection Act enforcement decree and the Standards for Securing the Safety of Personal Data; operational logs such as integration jobs and errors are kept for 3 months; integration session data is deleted 12 hours after last use. Records past these periods are purged daily by an automated job.

5. Third-Party Disclosure

The Company does not disclose personal data beyond the stated purposes unless the user consents or disclosure is required by law or a lawful authority request.

6. Processors

Supabase, Inc. provides cloud, database, and authentication services; Vercel Inc. provides application hosting, server execution, and server-log processing; Resend, Inc. sends authentication and notification email; Toss Payments Co., Ltd. (Korea) processes payments and payment methods. Each entrustment contract documents the ban on processing beyond its purpose, security measures, limits on sub-processing, management review, and liability, and the Company supervises its processors. Changes to processors or entrusted work are published in this Policy.

7. Overseas Transfers

Under PIPA Article 28-8(1)3, the Company discloses the following for overseas transfers made to entrust processing and storage. (1) Supabase, Inc. — Items: account email and authentication data, all service data entered or synced by the user including customer names and contacts, and attachments. Country: United States (database and storage region: AWS Asia/Seoul). Time and method: transferred and stored in real time over the network as the Service is used. Recipient: Supabase, Inc. (privacy@supabase.io). Purpose: cloud infrastructure, database, and authentication. Retention: until the entrustment contract ends or the Company requests deletion. (2) Vercel Inc. — Items: access IP, request headers and cookies, request/response data processed during server execution, and error logs. Country: United States (server execution region: Asia/Seoul). Time and method: transferred and processed in real time when the Service is accessed. Recipient: Vercel Inc. (privacy@vercel.com). Purpose: application hosting, server execution, and operational logs. Retention: until the entrustment contract ends; operational logs are deleted after the processor’s short-term retention period. (3) Resend, Inc. — Items: recipient email address and the subject and body of sent mail. Country: United States. Time and method: transferred in real time when email is sent. Recipient: Resend, Inc. (privacy@resend.com). Purpose: authentication and notification email. Retention: until the end of the processor’s send-log retention period. Users may refuse these transfers by contacting the privacy officer below; because the transfers are essential to providing the Service, refusal means the Service cannot be used and processing ends through withdrawal.

8. User Rights

Users may request access, correction, deletion, suspension, or withdrawal of consent through the privacy contact or support. Membership can be withdrawn under Settings > Account, subject to applicable law.

9. Destruction

Expired or no-longer-needed data is destroyed without delay. Electronic files are irrecoverably deleted and physical records are shredded or incinerated. Access and activity logs and integration session data with defined retention periods are purged daily by an automated job.

10. Security Measures

Encrypted authentication data and HTTPS; encrypted storage of payment-method and integration session data; database access controls and tenant isolation; access logs, access restrictions, and least-privilege controls. Company operators access user data only to the minimum extent needed for outage response, support, and abuse review, and such access is logged.

11. Cookies

Cookies are used for login sessions and Service operation. Browser settings can reject cookies, but login and other functions may then be unavailable. The Company does not use advertising or behavioral-analytics cookies.

12. Children Under 14

The Service is intended for businesses, is not directed to children under 14, and does not accept their registration. If the Company learns that data from a child under 14 has been collected, it destroys that data without delay.

13. Privacy Contact

The Company designates a privacy officer. Users may also contact the Personal Information Dispute Mediation Committee (1833-6972), Privacy Infringement Report Center (118), or relevant Korean cyber-investigation authorities.

Privacy officer: 황수지 · Contact: info@gagejangbu.com

14. Changes

Changes caused by law or Service updates will be announced with their effective date and details. Previous effective date: July 14, 2026 (this revision clarifies the Company’s processor role, completes the overseas-transfer disclosures, adds processors, states retention for integration sessions and logs, and adds the children-under-14 section).