Policy
Privacy Policy
How Surfaze processes personal information, who supports that processing, and how to exercise your rights.
Announced: August 15, 2026 · Effective: August 15, 2026
1. Controller and scope
사월이파리 (the “Company”) operates Surfaze and related websites. This policy explains how the Company processes personal information under the laws of the Republic of Korea, including the Personal Information Protection Act.
This English document is a convenience translation of the Korean Privacy Policy. If the two versions conflict, the Korean version prevails to the extent permitted by applicable law.
- Controller: 사월이파리
- Representative: 정현숙
- Registered address: 서울특별시 양천구 목동로19길 11, 한농빌딩 4층 557호(신정동)
- Contact: support@mail.surfaze.xyz, 010-5349-1717
2. Information, purpose, and retention
The Company processes the minimum information needed to provide accounts, workspaces, visibility collection, billing, support, and service security.
| Activity | Information | Purpose | Retention |
|---|---|---|---|
| Account and authentication | Email, name, account and authentication-provider identifiers; optional profile name and image. Supabase processes password credentials and the Company does not view the original password. | Registration, login, identity, security notices, and account management | Until account deletion, except records retained by law |
| Workspace and members | Workspace and brand names, domain, aliases, invitation email, member identifier, role, permissions, onboarding and settings | Workspace creation, invitations, access control, and collaboration | Until workspace deletion or member removal |
| Search and AI visibility | Keywords, prompts, competitors, country, language, device, channel, scan requests and results, search results, AI answers, citation URLs, reports, alerts, recommendations, and feedback | Collect and analyze search and AI visibility, provide metrics, reports, alerts, recommendations, and usage calculation | Until the item or workspace is deleted; irreversibly de-identified statistics may be retained |
| Subscription and payment | Order ID, plan, currency, subtotal, tax, total, billing state and cycle, card issuer/type/last four digits where available, encrypted Toss billing key, provider customer/payment identifiers, retry, cancellation, refund, and receipt records | Domestic or international payment, plan entitlement, fraud prevention, cancellation, refund, tax, and accounting | Payment-method data until replacement, deletion, or subscription end; transaction records for five years where required |
| Support and sales inquiry | Name, work email, company or brand, role, website, team size, inquiry type and message, response, result, and voluntarily attached material | Respond to inquiries, sales consultation, complaints, and disputes | One year from receipt; three years where consumer dispute records must be retained |
| Technical data | IP address, access time, path, cookies, session identifiers, browser, OS, device and screen data, internal account/workspace identifiers and role, feature events, error, performance, and security logs | Session operation, security, abuse prevention, troubleshooting, quality, and usability | Access and security logs generally up to three months; error events up to 90 days; analytics until the account or purpose ends or a valid deletion request is completed |
| Optional Slack integration | Incoming Webhook URL, workspace name, report or alert content, and delivery result | Send tests, alerts, and reports to the channel selected by the workspace | Until disconnection or workspace deletion; messages already sent follow the Slack workspace retention policy |
3. Collection methods and data minimization
- Information is collected when a person registers, authenticates, configures a workspace, enters tracking data, invites a member, makes a payment, connects Slack, submits an inquiry, or uses the service.
- Technical logs and product events may be generated automatically. Search and AI results are collected from supported external providers in response to customer configuration.
- Do not enter sensitive personal information or third-party personal information into keywords, prompts, brand fields, or support material unless you have a lawful business reason and authority to do so.
4. Retention required by law
| Record | Retention |
|---|---|
| Contract, withdrawal, payment, and supply records under Korean electronic commerce law | Five years |
| Consumer complaints and dispute handling records | Three years |
| Display and advertising records | Six months |
| Connection records required by communications law | Three months where applicable |
5. B2B roles and third-party disclosure
- For workspace customer data, the customer determines the business purpose and lawful basis for the information it enters. The Company processes that data to provide the contracted service.
- The Company does not sell personal information. It does not disclose personal information to an unrelated third party without consent unless disclosure is required or permitted by law, needed to protect life or safety, or necessary for a corporate transaction with appropriate safeguards.
- Workspace owners control member access. A member's activity within granted permissions is treated as workspace activity.
6. Processors
The Company may use processors only for the stated service purpose and manages them through contracts and reasonable oversight.
| Provider or category | Delegated work |
|---|---|
| Supabase | Authentication, database, and file or service infrastructure |
| Vercel | Web application hosting, delivery, and operational logs |
| Toss Payments | Payment method registration, approval, recurring payment, cancellation, refund, and receipt processing |
| Polar | Merchant of Record for international USD checkout, tax calculation and collection, recurring payment, cancellation, refund, invoice, and customer portal |
| Resend and configured email infrastructure | Transactional email, support inquiry receipt, forwarding, and report delivery |
| Slack, when connected by the customer | Delivery of tests, alerts, and reports to the selected workspace channel |
7. Overseas transfers
Some infrastructure, authentication, email, analysis, or customer-selected integration providers may process information outside Korea. The exact region can depend on the provider and workspace configuration.
- Transferred items are limited to the account, service, technical, or delivery data needed by that provider.
- Transfers occur through encrypted networks and are retained for the service period or the shorter period stated in this policy, subject to provider backup and legal obligations.
- Questions or objections may be sent to support@mail.surfaze.xyz. Restricting a necessary transfer may make the affected feature unavailable.
8. Payment information
- Toss Payments processes card details needed for payment. The Company stores only the provider identifiers, encrypted billing key, limited card display data, and transaction records needed to operate subscriptions.
- Domestic self-serve payments use Toss Payments in KRW and show supply price, VAT, and total before approval.
- International self-serve payments use Polar in USD. Polar acts as Merchant of Record, calculates applicable tax within the tax-inclusive catalogue price, and provides payment-method, invoice, and receipt management through its customer portal.
- Email sent to support@mail.surfaze.xyz is received by Resend and forwarded to the Company's configured support mailbox. The Company stores only delivery identifiers, status, and errors for webhook deduplication; it does not duplicate the message body or attachments in its application database.
- A pending or cancelled record is not an approved payment receipt.
10. Deletion
- Information is deleted or irreversibly de-identified without undue delay when the purpose and required retention period end.
- Electronic records are securely deleted so they cannot ordinarily be restored; physical records, if any, are shredded or destroyed through an appropriate process.
- Information retained by law is separated from active service data and used only for the required purpose during the retention period.
11. Data-subject rights
- A person may request access, correction, deletion, suspension, withdrawal of consent, or account closure through the service or by contacting support@mail.surfaze.xyz.
- The Company verifies identity or valid authority before responding and may limit a request where required or permitted by law. The reason will be explained.
- Deleting a workspace or account can affect other members and contracted records; ownership and legal-retention requirements are checked before completion.
12. Security safeguards
- The Company applies role-based access, authentication and session controls, encryption in transit, secret management, logging, backup, vulnerability and dependency management, and incident response appropriate to the service.
- Access to operational information is limited to people who need it for authorized duties and is reviewed when responsibilities change.
- No online service can promise absolute security. Members must protect their account and report suspected unauthorized access promptly.
13. Automated decisions and minors
- Surfaze may generate content recommendations or classifications, but it does not make a decision producing legal or similarly significant effects about an individual solely through automated processing.
- The service is intended for business users aged 18 or older and is not directed to children.
14. Privacy officer and complaints
- Privacy officer: 정현숙
- Email: support@mail.surfaze.xyz
- Telephone: 010-5349-1717
- The Company will review a valid privacy inquiry or complaint and respond within a reasonable period.
15. Remedies
- Privacy Infringement Report Center (KISA): privacy.kisa.or.kr, 118
- Personal Information Dispute Mediation Committee: kopico.go.kr, 1833-6972
- Supreme Prosecutors' Office: spo.go.kr, 1301
- National Police Agency cybercrime reporting: ecrm.police.go.kr, 182
16. Changes and previous version
- The Company may update this policy to reflect changes in law, service, processors, or processing practice.
- Ordinary changes are announced seven days before effect. Material expansion of collection, purpose, or impact on rights is announced at least 30 days before effect, and separate consent is obtained where legally required.
- Previous Korean Privacy Policy: July 11, 2026 through July 14, 2026.