This translation is provided for convenience. If it differs from the Korean version, the Korean version controls.
사월이파리 (the “Company”) processes personal data only as needed to provide BoothCatch and in accordance with applicable law. This policy covers member and inquiry data processed by the Company as controller and visitor data processed on an event organizer's instructions.
1. Controller and privacy contact
- Controller: 사월이파리 · Representative: 정현숙
- Address: 서울특별시 양천구 목동로19길 11, 한농빌딩 4층 557호(신정동)
- Privacy officer: Representative 정현숙
- Access, correction, deletion, complaints: support@mail.surfaze.xyz
2. Personal data, purposes, and retention
CSV is streamed to the browser on request. BoothCatch does not create a separate server-side XLSX or download object; users control retention and deletion of downloaded files.
| Data subject or area | Data processed | Purpose | Retention |
|---|---|---|---|
| Member account | Email, authentication-provider ID, name/profile, UI language, login and session records | Registration, authentication, security, service delivery, and restoring the account UI language | Until account withdrawal; security/audit records for the period required by law or security policy |
| Workspace and team | Workspace name, role, invitation email, invitation, acceptance, and permission history | Collaboration and access management | Until workspace deletion or the account relationship ends |
| Sales inquiry | Organization, contact name, email, inquiry type and message; optional phone, date, visitor estimate, and UTM data | Responding and product or contract consultation | One year from inquiry; contract and statutory retention applies if converted |
| Service records | IP address, User-Agent, request time, essential language/session cookies, error and security events | Maintaining login/language, abuse prevention, reliability, and security | Language cookie: up to one year; other records until purpose completion or provider/security-policy period |
| Payment and order | Internal order number, event, Polar order number, payment amount, tax and refund state | Event Pass issuance, confirmation, refunds, disputes, and accounting | Statutory e-commerce retention or until a dispute ends |
| Visitor lead | Fields configured by the organizer: name, company, title, department, email, phone, interests, answers, follow-up request, consent, staff notes, owner and state | Registration, duplicate review, draw and fulfillment, consultation, and follow-up | 30, 90, 180, or 365 days from collection, as configured |
| Business-card OCR | Card image, extracted contact details, and recognition state | Assisted staff entry and verification | Original image: 72 hours; confirmed lead: event retention period |
| Draw and fulfillment | Entry/win state, prize, draw time, fulfillment and correction history | Draw operations, inventory, fulfillment, and disputes | Linked lead retention or legally required dispute period |
3. Legal bases and children under 14
Processing relies on contract performance, consent, legal obligations, legitimate interests, or another basis permitted by law. Refusing optional data does not affect the base service, but a feature cannot operate without required data.
Member accounts are not directed to children under 14. An organizer collecting children's data must arrange required guardian consent and procedures and consult the Company in advance.
4. Event visitor data and processor relationship
The organizer or workspace operator determines the purpose and fields and acts as controller. The Company stores, classifies, exports, and deletes visitor data as processor under those settings and instructions.
Operators must disclose their identity, purpose, fields, retention, refusal rights, and obtain separate marketing consent where required. The Company does not independently use visitor leads beyond service delivery, security, and legal duties.
5. Third-party disclosure
The Company does not disclose personal data to third parties without separate consent or legal authority. Authorized team access for event operations is managed by the organizer. Lawful authority requests may be answered within applicable law.
6. Processors
The following providers perform tasks needed for the service. This policy is updated when the provider configuration changes.
| Processor | Task | Data |
|---|---|---|
| Supabase, Inc. / Amazon Web Services | Authentication, database, file storage, logs, backup | Member, workspace, event, lead, card, and draw data |
| Vercel Inc. | Website/server hosting, transmission, operational logs | Requests, transmitted data, IP, device and error data |
| Google LLC | Google sign-in, company-operated Gmail support inbox, Gemini API card OCR | Login identity, forwarded support email, card image and extraction request |
| Plus Five Five, Inc. (Resend) | Authentication and invitation email delivery; support email receipt, retrieval, and forwarding | Sender and recipient addresses, message body, headers, attachments, and delivery metadata |
| Upstash, Inc. | Request rate limiting for abuse prevention | Hashed request identifier and request count |
| Polar Software Inc. | Payment seller: payment collection, tax, receipts, refunds, and disputes | Buyer billing and order data; BoothCatch receives order, amount, and state data without card details |
7. Overseas transfer and processing
Global cloud, email, and OCR services may process data overseas. Declining essential overseas processing may limit the feature; ask support@mail.surfaze.xyz about alternatives.
The Company applies provider contracts, access controls, encryption, and other safeguards and updates this policy when processing changes.
| Recipient and country | Data and purpose | Time and method | Retention |
|---|---|---|---|
| Supabase, Inc., US / primary data region: AWS Seoul | Authentication, database, storage and support | Encrypted transfer while using the service | Service contract and customer-data retention |
| Vercel Inc., US and subprocessors | Web requests, server functions, operational logs | Page/API request transmission | Service delivery and contractual deletion |
| Google LLC, US and operating regions | Sign-in, company-operated Gmail support inbox, Gemini card OCR | When the feature is used or a support message is forwarded | Inquiry: one year; BoothCatch card image: 72 hours; Gemini request: Google contract/policy |
| Plus Five Five, Inc., US | Email delivery and support-message receipt, retrieval, and attachment forwarding | At email delivery or receipt | Inquiry retention and provider receipt/transmission-log period |
| Upstash, Inc., selected operating region | Rate limiting using hashed identifiers | At protected requests | Rate-limit window and contractual period |
| Polar Software Inc., US and payment regions | Payment, tax, receipt, and refund | Encrypted transfer during payment | Contractual, statutory and dispute period |
8. Statutory retention
Where law requires, contract, withdrawal, payment, complaint, and dispute records are segregated for the statutory period. Orders and refunds processed through Polar are retained for statutory and dispute-handling purposes.
9. Deletion
Data is destroyed without undue delay when retention ends or the purpose is met, using methods designed to prevent recovery. Electronic data is deleted from storage; physical output is shredded or incinerated.
Original card images are queued after 72 hours and leads after the configured event period. Account/workspace deletion follows checks for permission, ownership, and active work.
10. Data-subject rights
Data subjects may request access, correction, deletion, restriction, or withdrawal of consent. Members and inquirers may contact support@mail.surfaze.xyz. Event visitors should contact the organizer first; the Company assists on verified organizer instructions.
11. Cookies and automated processing
The service uses essential cookies for login, security, and display language. The language cookie lasts up to one year and restores the UI language from the account profile—not the workspace. Blocking cookies may limit login, protected screens, or language persistence.
The current release does not use advertising tracking or customer-behavior analytics cookies. Business-card OCR assists data entry but does not make decisions with legal effect about people.
12. Security and incident response
After identifying a personal-data incident, the Company assesses scope and gives required notices to affected people and authorities under applicable law.
- Role-based access, workspace isolation, and least privilege
- Encryption in transit, server-only secrets, expiring file URLs
- Error logging designed not to record raw personal data
- Idempotency keys, origin checks, rate limits, and validation
- Scheduled retention/deletion jobs and audit records
13. Remedies and policy changes
In Korea, privacy consultations or complaints may also be directed to the Privacy Infringement Report Center (118), Personal Information Dispute Mediation Committee, National Police Agency, or Supreme Prosecutors' Office.
Changes and their effective date are published in the service or website. Separate consent is obtained when required for adverse expansion of purpose, fields, or retention.
This policy takes effect on 2026-08-13.