Privacy Policy
Effective: May 11, 2026 · Last updated: July 20, 2026
Innostock (the "Company") complies with the Personal Information Protection Act and other applicable laws of the Republic of Korea, and establishes and discloses this Privacy Policy as follows to protect users' personal information. In this Policy, "Service" refers to Innostock provided by the Company.
1. Personal Information We Collect
The Company collects the following personal information to provide the Service.
| Category | Items collected | Method |
|---|---|---|
| Sign-up / inquiry | (Required) Name, company name, job title, contact (phone number), email address, country · (for inquiries) inquiry content | Entered directly by the user in the application form |
| Service use (account) | (Required) Email address, password (stored as a one-way hash and cannot be decrypted) | Entered at sign-up |
| Payment / settlement | (Card payment) payment history, transaction ID, billing email, country · (Bank transfer) depositor name, deposit records · (Tax invoice) business registration number, company name, representative name, business address | Entered/collected during payment (card details such as card numbers are handled directly by the payment processor) |
| Automatically collected | Access IP, cookies, service usage records, device/browser information | Generated automatically during use of the Service |
It is the user's responsibility to ensure that data they upload does not contain third parties' personal information such as customer names or contact details.
※ The Company does not, in principle, collect personal information of children under the age of 14.
2. Purpose of Collection and Use
- Responding to sign-up / inquiry requests, service guidance, and customer support
- Member identification and provision of the Service (demand forecasting, ordering, inventory management)
- Payment and settlement of fees, and issuance of tax invoices
- Service improvement through usage statistics and behavioral analysis, new feature announcements, and delivery of notices
- Prevention of misuse and ensuring service stability
※ The Company does not make automated decisions (including profiling) that produce legal effects concerning users or similarly significantly affect them using their personal information. Service outputs such as demand forecasts and order recommendations are a reference tool that supports the user's own decisions; the final judgment and responsibility rest with the user.
3. Retention and Use Period
As a rule, the Company destroys personal information without delay once the purpose of collection and use has been achieved. However, where retention for a certain period is required under applicable law, the information is kept for that period.
- Member information: until membership withdrawal (destroyed immediately upon withdrawal, except that email is retained for 30 days to prevent misuse)
- Sign-up requests: destroyed within 1 year after the processing purpose is achieved
- 1:1 inquiries: destroyed within 1 year after processing is completed
- Access logs: 6 months
- Records on contracts, payment, and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records on consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
- Records on labeling and advertising: 6 months (Act on Consumer Protection in Electronic Commerce)
- Books and supporting documents under tax law: 5 years (Framework Act on National Taxes, Corporate Tax Act)
- Information subject to a statutory retention obligation: the period prescribed by the relevant law
※ Payment is processed via a payment processor (Paddle) and bank transfer. Payment-method details such as card numbers are handled and stored directly by the payment processor, and the Company does not store them. Payment and transaction records are retained for the statutory periods above.
4. Provision to Third Parties
The Company does not use users' personal information beyond the scope stated in this Policy or provide it to third parties, except in the following cases:
- When the user has given prior consent
- When required by law or by a lawful request from an investigative agency
5. Outsourcing and Overseas Transfer of Processing
To provide the Service smoothly, the Company outsources personal information processing tasks as follows. Some processors are located overseas, and personal information may therefore be transferred abroad.
| Processor | Outsourced task (purpose) | Location · Overseas transfer | Items transferred | Website, Contact |
|---|---|---|---|---|
| Supabase, Inc. | Member authentication, database, infrastructure | Data storage location: Republic of Korea (AWS Seoul ap-northeast-2 region, stored domestically) · Headquarters: United States | Member account information | supabase.com, privacy@supabase.com |
| Vercel, Inc. | Service hosting and server operation | Overseas transfer: United States | Access IP, request information, server logs | vercel.com, privacy@vercel.com |
| Paddle.com Market Limited | Payment processing (Merchant of Record) | Overseas transfer: United Kingdom | Payment history, transaction ID, billing email, country | paddle.com, privacy@paddle.com |
| Google LLC | Web usage statistics analysis (Google Analytics) | Overseas transfer: United States | Access IP, cookie-based usage behavior and device information | policies.google.com/privacy, data-access-requests@google.com |
| Microsoft Corporation | Usability analysis (Microsoft Clarity — session replay / heatmaps) | Overseas transfer: United States | Page interactions (clicks/scrolls), access IP (※ personal information entered in forms is masked and is not transmitted) | clarity.microsoft.com/privacy, aka.ms/privacyresponse |
| Devro LABS (FormSubmit) | Inquiry / sign-up form delivery | Overseas transfer: Sri Lanka | Name, company name, job title, contact, email, country, and inquiry content entered in the form | formsubmit.co, support@formsubmit.co |
| Cloudflare, Inc. | Bot protection and automated sign-up prevention (Turnstile) | Overseas transfer: United States | Access IP, browser/device information | cloudflare.com, privacyquestions@cloudflare.com |
※ Processing of personal information by the above processors is subject to safeguards applied through outsourcing contracts under Article 26 of the Personal Information Protection Act. Member information is stored on servers within the Republic of Korea (Supabase Seoul region).
※ Timing and method of overseas transfer: transmitted automatically over the network at the time the Service is used. Retention/use period of the recipient: until the purpose of the outsourcing is achieved or the outsourcing contract terminates, within the scope of the purposes above.
※ Users may refuse the overseas transfer of their personal information by sending a list of the personal information they do not wish to be transferred to the Personal Information Protection Officer's email (support@getinnostock.com). However, because the above overseas transfers are essential to providing the Service (member authentication, data storage, payment, etc.), users who refuse the transfer may be unable to use all or part of the Service.
6. Rights of Data Subjects and Legal Representatives, and How to Exercise Them
Users (data subjects) and their legal representatives may at any time request access to, correction, deletion, or suspension of processing of their personal information. Such requests may be made via the Personal Information Protection Officer contact below, and the Company will act without delay.
In addition, under Article 35-2 of the Personal Information Protection Act, users may request that their personal information be transmitted to themselves or to another personal information controller or a specialized personal information management institution. The method of requesting transmission and of checking transmission status and records may be applied for via the Personal Information Protection Officer contact below, and the Company processes such requests within the scope prescribed by applicable law.
7. Destruction Procedure and Method
When personal information becomes unnecessary — for example, upon expiry of the retention period or achievement of the processing purpose — the Company destroys it within 5 days thereof.
- Electronic files: permanently deleted by a method that prevents recovery or reproduction
- Paper documents: shredded or incinerated
8. Measures to Ensure Security
a. Administrative measures — Establishment and implementation of an internal management plan; minimization of access privileges (least privilege)
b. Technical measures — One-way hash storage of passwords (cannot be decrypted), TLS 1.2+ encryption across the entire transmission path, per-user data isolation via database row-level security (RLS), enforcement of HTTPS and security headers (CSP, HSTS, X-Frame-Options), and blocking of abnormal access (rate limiting)
c. Backups — The Company does not operate routine backups of personal information.
※ For convenience, some data may be temporarily cached in the user's browser local storage (localStorage), and this copy may be stored in plain text on that device. We recommend logging out and clearing browser data on shared devices.
9. Operation of Cookies
The Company may use cookies to provide the Service, for user convenience, and for service usage and behavioral analytics (Google Analytics, Microsoft Clarity). Users may refuse the storage of cookies.
- You may refuse cookie storage in your web browser — Chrome: Settings > Privacy and security > Cookies and other site data / Edge: Settings > Cookies and site permissions / Safari: Preferences > Privacy > Manage cookies and website data / Firefox: Settings > Privacy & Security > Cookies and Site Data
- In each browser's settings you can choose "Block third-party cookies" or "Block all cookies."
- Resetting mobile advertising identifiers — iOS: Settings > Privacy & Security > Tracking (limit app tracking) / Android: Settings > Privacy > Ads (reset/delete advertising ID)
- If you refuse cookie storage, some Service features may be limited.
10. Personal Information Protection Officer
The Company designates a Personal Information Protection Officer who oversees matters relating to personal information processing.
- Name: Eyrom Moon (Personal Information Protection Officer)
- Phone: 070-8058-9569
- Email: support@getinnostock.com
Requests for access, correction, deletion, or suspension of processing of personal information are received and handled by the department below.
- Access request reception/processing: Personal Information Protection Officer (Eyrom Moon) · Email: support@getinnostock.com
11. Remedies for Infringement of Rights
For reports or consultation regarding personal information infringement, you may contact the following organizations (Korea):
- Personal Information Dispute Mediation Committee: 1833-6972 (privacy.go.kr)
- Personal Information Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Investigation: 1301
- National Police Agency Cyber Bureau: 182
12. Duty of Notice
Any addition, deletion, or modification of this Privacy Policy will be announced through the website's notices before it takes effect.
This English version is provided for reference only. In case of any conflict or difference in interpretation between the Korean and English versions, the Korean version shall prevail.