Privacy Policy
Effective date: [○○ ○○, 2026]
This English translation is provided for convenience only. In the event of any discrepancy, the Korean version shall prevail.
Imagineline Co., Ltd. (the “Company”) complies with the Personal Information Protection Act and other applicable laws, and establishes and discloses this Privacy Policy to protect users' personal information.
1. Personal Information Collected and Collection Methods
| Category | Items collected | Method |
|---|---|---|
| Sign-up (required) | Email address (ID), password, contact (mobile number), business name, address | Website sign-up form |
| Free audit request | Business name, area (address), category, contact or email, (optional) website URL | Audit request form |
| Paid service contract | Business registration number (for tax invoices), payment-related information | Contract and payment process |
| Automatically collected | IP address, cookies, access timestamps, service usage records | During service use |
| Marketing (optional consent) | Email address, contact number | Separate opt-in consent |
※ Payment card details (card numbers, etc.) are not stored by the Company; they are processed and retained by the payment gateway (PG) in accordance with applicable laws. For recurring billing, the Company stores only a payment-method identifier (billing key) issued by the PG, not card details.
2. Purposes of Processing
- Member management: confirming intent to join, identity verification, notices
- Service provision: generating and sending audit reports, building and operating websites, providing visibility reports, responding to inquiries
- Billing and settlement: subscription billing, payment notices, tax invoices, refunds
- Marketing and advertising (consenting users only): announcements of new services and events, personalized information
- Service improvement: usage analysis, quality enhancement
3. Retention and Use Period
- Personal information is destroyed without delay upon membership withdrawal, except that the following is retained as required by law:
| Records retained | Legal basis | Period |
|---|---|---|
| Records on contracts and withdrawal of offers | E-Commerce Act | 5 years |
| Records on payments and supply of goods | E-Commerce Act | 5 years |
| Records on consumer complaints and dispute handling | E-Commerce Act | 3 years |
| Records on labeling and advertising | E-Commerce Act | 6 months |
| Service access logs | Protection of Communications Secrets Act | 3 months |
2. Free audit request information is retained for [1 year] from collection and then destroyed (for consultation and follow-up purposes; destroyed immediately upon deletion request).
3. When a paid (subscription) service ends, website content and configuration data are retained for 60 days from the termination date to support resumption or transfer, then destroyed. If the member requests earlier deletion, the data is destroyed immediately, except for information the Company must retain under applicable laws.
4. Provision to Third Parties
The Company does not, in principle, provide users' personal information to third parties, except with the user's prior consent or as required by law.
5. Outsourcing of Processing
| Contractor | Outsourced work |
|---|---|
| [PortOne (Korea PortOne Co., Ltd.)] | Payment processing and payment agency (including recurring-billing key management) |
| [○○○ (KakaoTalk notification / SMS provider)] | Sending KakaoTalk notifications and SMS |
When concluding outsourcing contracts, the Company stipulates the contractor's data protection obligations under Article 26 of the Personal Information Protection Act and supervises compliance.
6. Cross-Border Transfers
To provide the Service, the Company outsources personal information processing to overseas providers as follows.
| Recipient | Country | Items transferred | Timing / method | Purpose | Retention |
|---|---|---|---|---|---|
| Supabase, Inc. (AWS [ap-northeast-2 Seoul] region) | USA (data stored in: [South Korea]) | Member information, service usage data | Network transmission during service use | Data storage and processing infrastructure | Until the outsourcing ends |
| Vercel Inc. | USA | Access IP, service usage records | Network transmission during service use | Website hosting and delivery infrastructure | Until the outsourcing ends |
| Anthropic, PBC | USA | Audited business information (name, address, category, etc.) | Network transmission during report generation | AI-based report copy generation | Destroyed immediately after processing (not used for training) |
Users may refuse cross-border transfers, in which case the provision of related services may be limited.
7. Destruction of Personal Information
- Procedure: personal information whose retention period has expired or whose processing purpose has been achieved is destroyed without delay.
- Method: electronic files are permanently deleted in an unrecoverable manner; printed materials are shredded or incinerated.
8. Users' Rights and How to Exercise Them
- Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information.
- Requests may be made via in-service settings or by email (support@imagineline.com), and the Company will act without delay.
- Users may withdraw marketing consent at any time (via the unsubscribe link in messages or by email request).
9. Cookies
- The Company may use cookies to provide personalized services.
- Users may refuse cookies through browser settings, in which case some services may be limited.
10. Security Measures
- Administrative: internal management plans, minimized access privileges
- Technical: encrypted password storage, encryption in transit (HTTPS), access control
- Physical: the physical security of the data center (cloud) follows the security framework of the infrastructure provider
11. Data Protection Officer
| Data Protection Officer | Seongho Jeong (CEO) |
|---|---|
| Contact | support@imagineline.com |
Users may report any privacy-related inquiries or complaints arising from service use to the Data Protection Officer, and the Company will respond promptly and in good faith.
12. Remedies for Rights Infringement
For reports or consultation regarding privacy infringements, contact:
- Personal Information Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation Division: 1301 / spo.go.kr
- National Police Agency Cyber Bureau: 182 (no area code) / ecrm.police.go.kr
13. Changes to This Policy
Any additions, deletions, or amendments to this policy will be announced via website notices at least 7 days before taking effect (30 days for material changes).
- Announcement date: [○○ ○○, 2026]
- Effective date: [○○ ○○, 2026]