Article 1 (General)
VanillaX Inc. ("the Company") establishes and publishes this Privacy Policy under Article 30 of the Personal Information Protection Act ("PIPA") to protect the personal data of data subjects and to handle related complaints promptly. It applies to "Dodam AI", the cross-border marketplace listing inspection service the Company operates.
The Company processes business data of the traders and staff who use the Service. It does not collect personal data of children under 14.
Article 2 (What we collect and how)
(1) We collect only the minimum needed to provide the Service.
- Context
- Sign-up
- Data collected
- Email address, password (stored one-way hashed), name
- Method
- Entered on the sign-up screen
- Required
- Required
- Context
- Workspace creation
- Data collected
- Organization name, default destination country, default marketplace
- Method
- Entered during onboarding
- Required
- Required
- Context
- Running an inspection
- Data collected
- Uploaded image files, product title, key features, description, product category
- Method
- Entered or uploaded on the inspection screen, or sent via the API
- Required
- Required
- Context
- Team invitations
- Data collected
- Email address of the invitee
- Method
- Entered on the members screen
- Required
- Optional
- Context
- Generated automatically in use
- Data collected
- IP address, timestamp, request path and response code, browser and OS information, cookies, records of inspections, downloads and API calls
- Method
- Generated automatically while you use the Service
- Required
- Required
- Context
- Marketing messages
- Data collected
- Email address, consent flag and the time consent was given
- Method
- Optional consent on the sign-up screen
- Required
- Optional
- Context
- Support and complaints
- Data collected
- Email address, the content of your enquiry, attachments
- Method
- Received by email
- Required
- Optional
| Context | Data collected | Method | Required |
|---|---|---|---|
| Sign-up | Email address, password (stored one-way hashed), name | Entered on the sign-up screen | Required |
| Workspace creation | Organization name, default destination country, default marketplace | Entered during onboarding | Required |
| Running an inspection | Uploaded image files, product title, key features, description, product category | Entered or uploaded on the inspection screen, or sent via the API | Required |
| Team invitations | Email address of the invitee | Entered on the members screen | Optional |
| Generated automatically in use | IP address, timestamp, request path and response code, browser and OS information, cookies, records of inspections, downloads and API calls | Generated automatically while you use the Service | Required |
| Marketing messages | Email address, consent flag and the time consent was given | Optional consent on the sign-up screen | Optional |
| Support and complaints | Email address, the content of your enquiry, attachments | Received by email | Optional |
(2) We do not collect sensitive data such as beliefs, political opinions, health or sex life, and we do not collect resident registration numbers. Please avoid including sensitive or unique identifying information in your uploads.
(3) Declining the optional items does not restrict sign-up or inspection in any way.
(4) When paid billing begins, payment method details and transaction records will additionally be processed through a payment gateway ({{결제대행사}}). We will amend and announce this Policy before that starts. The Company does not itself store card numbers or other payment credentials.
Article 3 (Purposes of processing)
We process personal data only for the following purposes, and will obtain consent in advance if a purpose changes.
- 1.Identifying and authenticating users, managing accounts and organizations, granting roles.
- 2.Running listing inspections, producing findings, applying automatic fixes and re-inspecting, delivering reports and outputs.
- 3.Issuing API keys, authenticating calls, metering usage and enforcing allowances.
- 4.Retaining your usage history so you can re-open your own results.
- 5.Handling enquiries and complaints and delivering announcements.
- 6.Preventing abuse, detecting intrusion attempts, keeping the Service stable.
- 7.Statistical analysis for product improvement, in a form that cannot identify anyone.
- 8.Telling users who opted in about new features and events.
- 9.Meeting obligations imposed by law.
Article 4 (Retention periods)
(1) We destroy personal data without delay once the purpose of collection has been achieved. The standard periods are as follows.
- Data
- Account data (email, name, password) and organization data
- Retention
- While the agreement is in force; destroyed within 30 days of a deletion request
- Data
- Uploaded images and product text, inspection results, fixed outputs
- Retention
- While the agreement is in force; destroyed within 30 days of a deletion request (immediately on an individual deletion request)
- Data
- API keys
- Retention
- Until revoked; kept 90 days after revocation for audit, then destroyed
- Data
- Access logs (IP, request path, response code)
- Retention
- 3 months from creation
- Data
- Marketing consent records
- Retention
- Until consent is withdrawn; after withdrawal only the fact of withdrawal is kept for 3 years
- Data
- Records of consent to the Terms and this Policy
- Retention
- 5 years after the agreement ends, to handle disputes
| Data | Retention |
|---|---|
| Account data (email, name, password) and organization data | While the agreement is in force; destroyed within 30 days of a deletion request |
| Uploaded images and product text, inspection results, fixed outputs | While the agreement is in force; destroyed within 30 days of a deletion request (immediately on an individual deletion request) |
| API keys | Until revoked; kept 90 days after revocation for audit, then destroyed |
| Access logs (IP, request path, response code) | 3 months from creation |
| Marketing consent records | Until consent is withdrawn; after withdrawal only the fact of withdrawal is kept for 3 years |
| Records of consent to the Terms and this Policy | 5 years after the agreement ends, to handle disputes |
(2) The 30-day grace period after account deletion is the minimum needed to recover from mistaken deletion and to prevent abusive re-registration. If you ask for immediate destruction, we destroy everything except items we must keep by law.
(3) The following are kept separately for the periods set by law.
- Records
- Contracts and withdrawal of subscription
- Period
- 5 years
- Legal basis
- E-Commerce Consumer Protection Act, Article 6
- Records
- Payment and supply of goods or services
- Period
- 5 years
- Legal basis
- E-Commerce Consumer Protection Act, Article 6
- Records
- Consumer complaints and dispute handling
- Period
- 3 years
- Legal basis
- E-Commerce Consumer Protection Act, Article 6
- Records
- Labelling and advertising
- Period
- 6 months
- Legal basis
- E-Commerce Consumer Protection Act, Article 6
- Records
- Electronic financial transactions
- Period
- 5 years
- Legal basis
- Electronic Financial Transactions Act, Article 22
- Records
- Tax invoices and transaction evidence
- Period
- 5 years
- Legal basis
- Framework Act on National Taxes, Article 85-3
- Records
- Access (login) logs
- Period
- At least 3 months
- Legal basis
- Protection of Communications Secrets Act, Article 15-2
| Records | Period | Legal basis |
|---|---|---|
| Contracts and withdrawal of subscription | 5 years | E-Commerce Consumer Protection Act, Article 6 |
| Payment and supply of goods or services | 5 years | E-Commerce Consumer Protection Act, Article 6 |
| Consumer complaints and dispute handling | 3 years | E-Commerce Consumer Protection Act, Article 6 |
| Labelling and advertising | 6 months | E-Commerce Consumer Protection Act, Article 6 |
| Electronic financial transactions | 5 years | Electronic Financial Transactions Act, Article 22 |
| Tax invoices and transaction evidence | 5 years | Framework Act on National Taxes, Article 85-3 |
| Access (login) logs | At least 3 months | Protection of Communications Secrets Act, Article 15-2 |
(4) Data kept under law is used only for that retention purpose and for nothing else.
Article 5 (Disclosure to third parties)
(1) We do not provide your personal data to third parties.
(2) The exceptions are:
- 1.You gave separate, prior consent.
- 2.A specific provision of law requires it.
- 3.An investigative authority requests it by presenting a warrant or equivalent under the procedure and in the manner prescribed by law.
(3) Even under paragraph (2)3, we verify that the request is lawful and in scope, provide only the minimum necessary, and tell you about it unless the law forbids us from doing so.
(4) Processors needed to operate the Service are disclosed in Article 6 and cross-border transfers in Article 7. Entrusting processing and transferring abroad are distinct from disclosure to a third party.
Article 6 (Processors)
(1) To run the Service we entrust processing as follows.
- Processor
- Supabase Inc.
- Purpose of the entrusted work
- Database, account authentication and uploaded-file storage
- Processing location
- Seoul region (ap-northeast-2), Republic of Korea; operational support accesses remotely from the United States
- Retention
- Until the processing agreement ends, or within 30 days of account deletion
- Processor
- Vercel Inc.
- Purpose of the entrusted work
- Web application hosting, request routing, access logging
- Processing location
- United States (global edge network)
- Retention
- Until the processing agreement ends. Access logs for up to 30 days
- Processor
- Google LLC (Gemini API)
- Purpose of the entrusted work
- Analysis of product images and product copy to enrich inspection results
- Processing location
- United States
- Retention
- Deleted as soon as the request is served. Not used to train models
- Processor
- OpenAI, L.L.C.
- Purpose of the entrusted work
- Generation of example images for fix suggestions
- Processing location
- United States
- Retention
- Deleted as soon as the request is served. Not used to train models
- Processor
- Brave Software, Inc. (Brave Search API)
- Purpose of the entrusted work
- Search for marketplace rule sources
- Processing location
- United States
- Retention
- Only the search query is sent; no personal data or uploaded content is sent
| Processor | Purpose of the entrusted work | Processing location | Retention |
|---|---|---|---|
| Supabase Inc. | Database, account authentication and uploaded-file storage | Seoul region (ap-northeast-2), Republic of Korea; operational support accesses remotely from the United States | Until the processing agreement ends, or within 30 days of account deletion |
| Vercel Inc. | Web application hosting, request routing, access logging | United States (global edge network) | Until the processing agreement ends. Access logs for up to 30 days |
| Google LLC (Gemini API) | Analysis of product images and product copy to enrich inspection results | United States | Deleted as soon as the request is served. Not used to train models |
| OpenAI, L.L.C. | Generation of example images for fix suggestions | United States | Deleted as soon as the request is served. Not used to train models |
| Brave Software, Inc. (Brave Search API) | Search for marketplace rule sources | United States | Only the search query is sent; no personal data or uploaded content is sent |
(2) Our processing agreements set out, in writing, technical and organisational safeguards, restrictions on sub-processing, supervision of the processor, and liability including damages.
(3) If the entrusted work or the processor changes, we publish the change in this Policy.
Article 7 (Cross-border transfers)
(1) To provide the Service we transfer personal data abroad as follows.
- Recipient
- Supabase Inc. (support@supabase.io)
- Country
- United States (data stored in the Seoul region, Republic of Korea)
- Time and method of transfer
- Transmitted over TLS when you use the service
- Data transferred
- Email, name, organization name, uploaded images, product text, access logs
- Purpose
- Operating the database, authentication and storage, and incident response
- Retention
- Deleted within 30 days of account deletion
- Recipient
- Vercel Inc. (privacy@vercel.com)
- Country
- United States
- Time and method of transfer
- Transmitted over TLS with each page or API request
- Data transferred
- IP address, timestamp, request path, browser information
- Purpose
- Hosting the web application, security and error handling
- Retention
- Up to 30 days
- Recipient
- Google LLC (represented by Google Ireland Ltd., privacy-emea@google.com)
- Country
- United States
- Time and method of transfer
- Sent over the API when an inspection runs
- Data transferred
- Uploaded images, product title and description text
- Purpose
- AI enrichment of rule-based inspection results
- Retention
- Deleted as soon as the request is served
- Recipient
- OpenAI, L.L.C. (privacy@openai.com)
- Country
- United States
- Time and method of transfer
- Sent over the API when an example image is requested
- Data transferred
- The image to be fixed and the fix instruction text
- Purpose
- Generating example images for fix suggestions
- Retention
- Deleted as soon as the request is served
- Recipient
- Brave Software, Inc. (privacy@brave.com)
- Country
- United States
- Time and method of transfer
- Sent over the API when rule sources are searched
- Data transferred
- Search terms (marketplace, country, rule keywords)
- Purpose
- Collecting citations for marketplace rules
- Retention
- No transfer (contains no personal data)
| Recipient | Country | Time and method of transfer | Data transferred | Purpose | Retention |
|---|---|---|---|---|---|
| Supabase Inc. (support@supabase.io) | United States (data stored in the Seoul region, Republic of Korea) | Transmitted over TLS when you use the service | Email, name, organization name, uploaded images, product text, access logs | Operating the database, authentication and storage, and incident response | Deleted within 30 days of account deletion |
| Vercel Inc. (privacy@vercel.com) | United States | Transmitted over TLS with each page or API request | IP address, timestamp, request path, browser information | Hosting the web application, security and error handling | Up to 30 days |
| Google LLC (represented by Google Ireland Ltd., privacy-emea@google.com) | United States | Sent over the API when an inspection runs | Uploaded images, product title and description text | AI enrichment of rule-based inspection results | Deleted as soon as the request is served |
| OpenAI, L.L.C. (privacy@openai.com) | United States | Sent over the API when an example image is requested | The image to be fixed and the fix instruction text | Generating example images for fix suggestions | Deleted as soon as the request is served |
| Brave Software, Inc. (privacy@brave.com) | United States | Sent over the API when rule sources are searched | Search terms (marketplace, country, rule keywords) | Collecting citations for marketplace rules | No transfer (contains no personal data) |
(2) Supabase stores data in the Seoul region of the Republic of Korea, but staff located in the United States may access it remotely for operational support, so it is disclosed here as a cross-border transfer.
Article 8 (How we destroy personal data)
(1) We destroy personal data without delay once the retention period ends or the purpose is achieved.
(2) Procedure: data due for destruction is identified and destroyed with the approval of the privacy officer. Data that must be retained by law is moved to a separate database with restricted access and destroyed when its period ends.
(3) Method: electronic records are permanently deleted by a method that prevents recovery; uploaded images and outputs are deleted from storage objects and removed from backups. Printed records are shredded or incinerated.
(4) Anything remaining on backup media is overwritten and lost once the backup retention cycle (up to 30 days) has passed.
Article 9 (Your rights and how to exercise them)
(1) You may exercise the following rights at any time.
- 1.Request access to your personal data.
- 2.Request correction of anything inaccurate.
- 3.Request deletion.
- 4.Request suspension of processing.
- 5.Withdraw consent, including consent to marketing messages.
(2) Exercise them directly in the settings screens, or by emailing admin@vanillax.co. We act within 10 days of receiving a request and tell you the outcome.
- Right
- Access and correction
- How
- Settings › Profile for your name and language; Settings › Organization for organization details
- Right
- Deletion
- How
- Deleting an inspection from the list also deletes its uploads and results
- Right
- Suspension and account deletion
- How
- Use account deletion in Settings, or email admin@vanillax.co
- Right
- Withdrawing marketing consent
- How
- Turn it off in the 'Your consent record' card at /legal, use the unsubscribe link in any message, or email admin@vanillax.co
| Right | How |
|---|---|
| Access and correction | Settings › Profile for your name and language; Settings › Organization for organization details |
| Deletion | Deleting an inspection from the list also deletes its uploads and results |
| Suspension and account deletion | Use account deletion in Settings, or email admin@vanillax.co |
| Withdrawing marketing consent | Turn it off in the 'Your consent record' card at /legal, use the unsubscribe link in any message, or email admin@vanillax.co |
(3) You may act through a legal representative or an authorised agent. In that case a power of attorney in the form of Annex 11 to the Notice on Personal Information Processing Methods must be submitted.
(4) Access and suspension requests may be restricted where the law allows, and data that another law requires us to collect cannot be deleted. We tell you the reason if that happens.
Article 11 (Security measures)
We take the following measures to keep personal data safe.
- 1.Organisational: an internal management plan, the smallest possible number of staff handling personal data, separated access rights, and regular training.
- 2.Technical: access-right management, row-level security in the database so organizations are isolated from each other, one-way password hashing, TLS in transit and encryption at rest.
- 3.Access control: uploads are stored in a private bucket and can be opened only through short-lived signed URLs.
- 4.Log retention: access logs of the personal-data processing system are kept for at least 3 months and protected against tampering.
- 5.Physical: we follow the data-centre security policies of our cloud providers and operate no server room of our own.
Article 12 (Privacy officer and access requests)
(1) The Company designates a privacy officer to oversee personal data processing and to handle complaints and remedies for data subjects.
- Item
- Name and title
- Detail
- {{개인정보보호책임자}}
- Item
- Team
- Detail
- VanillaX Inc. Operations
- Item
- Detail
- admin@vanillax.co
- Item
- Phone
- Detail
- +82 10-4953-0235
- Item
- Address
- Detail
- Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea
| Item | Detail |
|---|---|
| Name and title | {{개인정보보호책임자}} |
| Team | VanillaX Inc. Operations |
| admin@vanillax.co | |
| Phone | +82 10-4953-0235 |
| Address | Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea |
(2) Requests for access, correction, deletion or suspension go to the same contact. We act immediately on receipt and report the outcome within 10 days.
Article 13 (Where to seek redress)
You may apply to the following bodies for mediation or advice about a privacy infringement. They are independent of the Company; use them if you are not satisfied with our handling or need further help.
- Body
- Personal Information Dispute Mediation Committee
- Role
- Privacy dispute mediation, collective mediation
- Phone
- +82-1833-6972
- Website
- www.kopico.go.kr
- Body
- Privacy Infringement Report Centre (KISA)
- Role
- Reporting infringements, advice
- Phone
- 118 (in Korea)
- Website
- privacy.kisa.or.kr
- Body
- Supreme Prosecutors' Office, Cyber Investigation Division
- Role
- Criminal investigation of privacy offences
- Phone
- 1301 (in Korea)
- Website
- www.spo.go.kr
- Body
- Korean National Police Agency, Cyber Bureau
- Role
- Criminal investigation of privacy offences
- Phone
- 182 (in Korea)
- Website
- ecrm.police.go.kr
| Body | Role | Phone | Website |
|---|---|---|---|
| Personal Information Dispute Mediation Committee | Privacy dispute mediation, collective mediation | +82-1833-6972 | www.kopico.go.kr |
| Privacy Infringement Report Centre (KISA) | Reporting infringements, advice | 118 (in Korea) | privacy.kisa.or.kr |
| Supreme Prosecutors' Office, Cyber Investigation Division | Criminal investigation of privacy offences | 1301 (in Korea) | www.spo.go.kr |
| Korean National Police Agency, Cyber Bureau | Criminal investigation of privacy offences | 182 (in Korea) | ecrm.police.go.kr |
If your rights or interests are harmed by a disposition or omission by the Company in response to a request under PIPA Articles 35 (access), 36 (correction or deletion) or 37 (suspension), you may also file an administrative appeal under the Administrative Appeals Act. (Central Administrative Appeals Commission, 110 in Korea, www.simpan.go.kr)
Article 14 (Changes to this Policy)
(1) This Policy applies from its effective date. Additions, deletions or corrections are announced inside the Service at least 7 days beforehand, or at least 30 days beforehand where user rights change materially.
(2) Earlier versions are available on request. The change history is as follows.
- Version
- 1.0
- Effective
- 2026-09-03
- Change
- First published
| Version | Effective | Change |
|---|---|---|
| 1.0 | 2026-09-03 | First published |
Revision history
- Version 1.0First published
Read alongside
Other terms and policies that apply together with this document.
Questions
Send questions or correction requests about these documents to the address below. We reply within 3 business days.
VanillaX Inc. · Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea