Policy

Privacy Policy

How Surfaze processes personal information, who supports that processing, and how to exercise your rights.

Announced: August 15, 2026 · Effective: August 15, 2026

1. Controller and scope

사월이파리 (the “Company”) operates Surfaze and related websites. This policy explains how the Company processes personal information under the laws of the Republic of Korea, including the Personal Information Protection Act.

This English document is a convenience translation of the Korean Privacy Policy. If the two versions conflict, the Korean version prevails to the extent permitted by applicable law.

  • Controller: 사월이파리
  • Representative: 정현숙
  • Registered address: 서울특별시 양천구 목동로19길 11, 한농빌딩 4층 557호(신정동)
  • Contact: support@mail.surfaze.xyz, 010-5349-1717

2. Information, purpose, and retention

The Company processes the minimum information needed to provide accounts, workspaces, visibility collection, billing, support, and service security.

ActivityInformationPurposeRetention
Account and authenticationEmail, name, account and authentication-provider identifiers; optional profile name and image. Supabase processes password credentials and the Company does not view the original password.Registration, login, identity, security notices, and account managementUntil account deletion, except records retained by law
Workspace and membersWorkspace and brand names, domain, aliases, invitation email, member identifier, role, permissions, onboarding and settingsWorkspace creation, invitations, access control, and collaborationUntil workspace deletion or member removal
Search and AI visibilityKeywords, prompts, competitors, country, language, device, channel, scan requests and results, search results, AI answers, citation URLs, reports, alerts, recommendations, and feedbackCollect and analyze search and AI visibility, provide metrics, reports, alerts, recommendations, and usage calculationUntil the item or workspace is deleted; irreversibly de-identified statistics may be retained
Subscription and paymentOrder ID, plan, currency, subtotal, tax, total, billing state and cycle, card issuer/type/last four digits where available, encrypted Toss billing key, provider customer/payment identifiers, retry, cancellation, refund, and receipt recordsDomestic or international payment, plan entitlement, fraud prevention, cancellation, refund, tax, and accountingPayment-method data until replacement, deletion, or subscription end; transaction records for five years where required
Support and sales inquiryName, work email, company or brand, role, website, team size, inquiry type and message, response, result, and voluntarily attached materialRespond to inquiries, sales consultation, complaints, and disputesOne year from receipt; three years where consumer dispute records must be retained
Technical dataIP address, access time, path, cookies, session identifiers, browser, OS, device and screen data, internal account/workspace identifiers and role, feature events, error, performance, and security logsSession operation, security, abuse prevention, troubleshooting, quality, and usabilityAccess and security logs generally up to three months; error events up to 90 days; analytics until the account or purpose ends or a valid deletion request is completed
Optional Slack integrationIncoming Webhook URL, workspace name, report or alert content, and delivery resultSend tests, alerts, and reports to the channel selected by the workspaceUntil disconnection or workspace deletion; messages already sent follow the Slack workspace retention policy

3. Collection methods and data minimization

  • Information is collected when a person registers, authenticates, configures a workspace, enters tracking data, invites a member, makes a payment, connects Slack, submits an inquiry, or uses the service.
  • Technical logs and product events may be generated automatically. Search and AI results are collected from supported external providers in response to customer configuration.
  • Do not enter sensitive personal information or third-party personal information into keywords, prompts, brand fields, or support material unless you have a lawful business reason and authority to do so.

5. B2B roles and third-party disclosure

  • For workspace customer data, the customer determines the business purpose and lawful basis for the information it enters. The Company processes that data to provide the contracted service.
  • The Company does not sell personal information. It does not disclose personal information to an unrelated third party without consent unless disclosure is required or permitted by law, needed to protect life or safety, or necessary for a corporate transaction with appropriate safeguards.
  • Workspace owners control member access. A member's activity within granted permissions is treated as workspace activity.

6. Processors

The Company may use processors only for the stated service purpose and manages them through contracts and reasonable oversight.

Provider or categoryDelegated work
SupabaseAuthentication, database, and file or service infrastructure
VercelWeb application hosting, delivery, and operational logs
Toss PaymentsPayment method registration, approval, recurring payment, cancellation, refund, and receipt processing
PolarMerchant of Record for international USD checkout, tax calculation and collection, recurring payment, cancellation, refund, invoice, and customer portal
Resend and configured email infrastructureTransactional email, support inquiry receipt, forwarding, and report delivery
Slack, when connected by the customerDelivery of tests, alerts, and reports to the selected workspace channel

7. Overseas transfers

Some infrastructure, authentication, email, analysis, or customer-selected integration providers may process information outside Korea. The exact region can depend on the provider and workspace configuration.

  • Transferred items are limited to the account, service, technical, or delivery data needed by that provider.
  • Transfers occur through encrypted networks and are retained for the service period or the shorter period stated in this policy, subject to provider backup and legal obligations.
  • Questions or objections may be sent to support@mail.surfaze.xyz. Restricting a necessary transfer may make the affected feature unavailable.

8. Payment information

  • Toss Payments processes card details needed for payment. The Company stores only the provider identifiers, encrypted billing key, limited card display data, and transaction records needed to operate subscriptions.
  • Domestic self-serve payments use Toss Payments in KRW and show supply price, VAT, and total before approval.
  • International self-serve payments use Polar in USD. Polar acts as Merchant of Record, calculates applicable tax within the tax-inclusive catalogue price, and provides payment-method, invoice, and receipt management through its customer portal.
  • Email sent to support@mail.surfaze.xyz is received by Resend and forwarded to the Company's configured support mailbox. The Company stores only delivery identifiers, status, and errors for webhook deduplication; it does not duplicate the message body or attachments in its application database.
  • A pending or cancelled record is not an approved payment receipt.

9. Cookies and analytics

  • Essential cookies and local storage maintain authentication, language preference, security, and requested product state.
  • Product analytics and error tools may process pseudonymous account/workspace identifiers, feature events, device information, page path, performance data, and error context to improve reliability and usability.
  • Users can restrict cookies through browser settings, but blocking essential storage can prevent login or other requested features.

10. Deletion

  • Information is deleted or irreversibly de-identified without undue delay when the purpose and required retention period end.
  • Electronic records are securely deleted so they cannot ordinarily be restored; physical records, if any, are shredded or destroyed through an appropriate process.
  • Information retained by law is separated from active service data and used only for the required purpose during the retention period.

11. Data-subject rights

  • A person may request access, correction, deletion, suspension, withdrawal of consent, or account closure through the service or by contacting support@mail.surfaze.xyz.
  • The Company verifies identity or valid authority before responding and may limit a request where required or permitted by law. The reason will be explained.
  • Deleting a workspace or account can affect other members and contracted records; ownership and legal-retention requirements are checked before completion.

12. Security safeguards

  • The Company applies role-based access, authentication and session controls, encryption in transit, secret management, logging, backup, vulnerability and dependency management, and incident response appropriate to the service.
  • Access to operational information is limited to people who need it for authorized duties and is reviewed when responsibilities change.
  • No online service can promise absolute security. Members must protect their account and report suspected unauthorized access promptly.

13. Automated decisions and minors

  • Surfaze may generate content recommendations or classifications, but it does not make a decision producing legal or similarly significant effects about an individual solely through automated processing.
  • The service is intended for business users aged 18 or older and is not directed to children.

14. Privacy officer and complaints

  • Privacy officer: 정현숙
  • Email: support@mail.surfaze.xyz
  • Telephone: 010-5349-1717
  • The Company will review a valid privacy inquiry or complaint and respond within a reasonable period.

15. Remedies

  • Privacy Infringement Report Center (KISA): privacy.kisa.or.kr, 118
  • Personal Information Dispute Mediation Committee: kopico.go.kr, 1833-6972
  • Supreme Prosecutors' Office: spo.go.kr, 1301
  • National Police Agency cybercrime reporting: ecrm.police.go.kr, 182

16. Changes and previous version

  • The Company may update this policy to reflect changes in law, service, processors, or processing practice.
  • Ordinary changes are announced seven days before effect. Material expansion of collection, purpose, or impact on rights is announced at least 30 days before effect, and separate consent is obtained where legally required.
  • Previous Korean Privacy Policy: July 11, 2026 through July 14, 2026.