Roastive Privacy Policy

Reference translation. This English text is provided for convenience only. The Korean version at /privacy is the authoritative original; in the event of any discrepancy in interpretation, the Korean version prevails.

STANDARD SQUARE COFFEELAB (the "Company") complies with the personal data protection provisions of applicable laws, including the Personal Information Protection Act ("PIPA") and the Act on Promotion of Information and Communications Network Utilization and Information Protection, and establishes and discloses this Privacy Policy as follows in order to protect users' personal data.


1. Categories of Personal Data Processed

The Company collects and uses the following categories of personal data in order to provide the Service.

1.1 On registration (required)

1.2 When operating a Roastery (workspace)

1.3 When paying for Paid Services

1.4 Information collected automatically during use of the Service

1.5 Content entered into the Service by Members

1.6 When applying to the Partner Roaster programme

Where a person applies to the Partner Roaster recruitment programme operated by the Company, the following items are collected regardless of whether that person is a Member.

Required items

Optional items

An application may be submitted without completing the optional items, and the Company does not refuse to accept an application on the ground that they were not completed.

Photographs of roasting machines that are submitted are used solely for the purpose of confirming the roaster model and installation environment, and are not disclosed or used for marketing outside the purpose of review. Where separate use is required, individual consent is obtained in advance.

1.7 Employee health examination certificates (sensitive personal data) entered by Members

To manage the employee health examination obligation under Article 40 of the Food Sanitation Act and Article 49 of its Enforcement Rule, a Member (Roastery) may register the following information about its employees in the "Employee Health Certificates" feature of the Service.

A health examination certificate constitutes sensitive personal data (health information) under Article 23 of PIPA. The controller of this data is the Member (Roastery) that employs the person; the Company processes it solely as a processor entrusted by the Member with storage and management under Article 26 of PIPA. Before registering, the Member must obtain the employee's separate consent to the collection and use of the sensitive data, and the Company permits registration only after the Member records that confirmation. The Company does not use this data for any purpose other than the entrusted work (storage, controlled viewing and expiry reminders), does not provide it to third parties, and excludes it from automated text recognition (OCR) and other external AI processing.

2. Purposes of Processing Personal Data

The Company processes collected personal data for the following purposes, and obtains prior consent where the purpose of processing changes.

PurposeCategories processed
Member management (confirming intent to register, identification and authentication, prevention of unauthorized use)Email, password, name
Service provision (roastery, profile, inventory and order management)Content entered by Members, Roastery information
Payment and settlement for Paid ServicesPayment method, transaction history, business information
Tax invoice issuance and accountingBusiness registration number, representative's name
Customer support and complaint handlingEmail, mobile phone number, enquiry content
Security (prevention of fraudulent use, concurrent session limit, incident response)Access logs, IP, session information
Fulfilment of statutory obligations (Electronic Commerce Act, Value-Added Tax Act, etc.)Transaction and payment records
Statistical analysis for service improvementAutomatically collected information (after pseudonymization or anonymization)
Operation of the Partner Roaster programme (receipt of applications, review of eligibility and roaster compatibility, notification of selection results)Items collected under Section 1.6
Supporting the Member's (Roastery's) management of employee health examination obligations — limited to the entrusted storage, controlled viewing and expiry remindersItems in Article 1.7 (including sensitive data)

3. Retention and Use Period of Personal Data

  1. The Company retains and uses a Member's personal data from the time of registration until the Member withdraws.

  2. However, in the following cases, data is retained for the periods specified even after withdrawal.

    CategoryRetention periodLegal basis
    Records on contracts or withdrawal of subscription5 yearsAct on Consumer Protection in Electronic Commerce
    Records on payment and supply of goods5 yearsAct on Consumer Protection in Electronic Commerce
    Records on consumer complaints or dispute handling3 yearsAct on Consumer Protection in Electronic Commerce
    VAT-related records (tax invoices, etc.)5 yearsValue-Added Tax Act
    Records on labelling and advertising6 monthsAct on Consumer Protection in Electronic Commerce
    Records on collection, processing and use of credit information3 yearsCredit Information Use and Protection Act
    Access records under the Protection of Communications Secrets Act3 monthsProtection of Communications Secrets Act
    Records on fraudulent use1 yearPrevention of fraudulent use
  3. Content entered into the Service by a Member (roasting profiles and the like) is destroyed immediately upon withdrawal or within a reasonable period thereafter. The handling of content shared with other Members is subject to separate guidance.

  4. Partner Roaster application information collected under Section 1.6 (including submitted photographs) is destroyed within 90 days from the time notification of the selection results for that recruitment round is completed. Where an applicant is selected and converts to Member status, the items necessary for provision of the Service are retained under Paragraph 1.

  5. Employee health examination certificates under Article 1.7 (sensitive data) are destroyed — the original file and its registration record — as soon as the Member deletes the employee or destroys the document in the Service, and upon the Member's withdrawal in accordance with the preceding paragraphs. Access records of viewing, registration and destruction are, however, retained for two years pursuant to Article 8 of the Standards for Measures to Ensure the Safety of Personal Information and then destroyed.

4. Provision of Personal Data to Third Parties

  1. The Company does not provide a data subject's personal data to third parties except where Articles 17 and 18 of PIPA apply, such as where separate consent has been obtained from the data subject or where there is a special provision of law.

  2. In the following cases, personal data may be provided to third parties on a statutory basis or with the Member's consent.

    RecipientPurpose of provisionCategories providedRetention period
    Judicial and investigative authoritiesWhere there is a lawful request under applicable lawCategories prescribed by lawPeriod prescribed by law
    Counterparty to a disputeFor resolution of a dispute between Members, with the Member's consentMinimum information relating to the disputeUntil the dispute concludes
  3. Transfers of personal data to the payment service provider and cloud infrastructure operators are governed by Section 5 (Outsourcing of Personal Data Processing) and Section 6 (Cross-border Transfer of Personal Data) of this Policy.

5. Outsourcing of Personal Data Processing

In order to provide a smooth and improved Service, the Company outsources personal data processing tasks as follows. When outsourcing, the Company specifies obligations for safe processing through outsourcing agreements pursuant to Article 26 of PIPA.

ProcessorOutsourced taskCategories outsourced
Supabase Inc. (incorporated in the United States; data centres in Seoul, Korea / Tokyo, Japan — see Section 6 of this Policy)Operation of database, authentication, storage and serverless functionsMember information, content entered by Members, access logs, session information
Toss Payments Co., Ltd.Credit card payment processing, Billing Key issuance and recurring billing, payment history managementCard issuer and partial card number, Billing Key, payment amount and date/time, Member identifier
Supabase Inc.Sending authentication-related emails such as registration and password reset (Supabase Auth)Email address, name
Linkhub Co., Ltd. (Popbill)Delegated issuance of electronic tax invoices (Article 69 of the Enforcement Decree of the Value-Added Tax Act), transmission to the National Tax Service, retention of issuance history, processing of emails sent to purchasersMember's (supplier's) business registration number, trade name, representative's name, place-of-business address, business type and item, email; purchaser's (recipient's) business registration number, trade name, representative's name, email; transaction amount
Google LLC (Google Analytics — United States; see Section 6 of this Policy)Analysis of website visit and usage statistics (only where analytics cookies are consented to)Pages visited, events (button clicks, scrolling, etc.), acquisition source (including UTM), device and browser information, approximate location (country, city), cookie IDs of an advertising-identifier nature (directly identifying information such as name or email is not collected)

When concluding outsourcing agreements, the Company specifies the following matters pursuant to Article 26 of PIPA.

Where a processor changes or the content of an outsourced task changes, the Company discloses this through this Policy.

6. Cross-border Transfer of Personal Data

For the operation of the Service, certain personal data may be transferred abroad as follows.

RecipientCountry of transferDate and method of transferCategories transferredPurpose of transferRetention and use period
Supabase Inc. (operating entity)Operational support: United States and othersContinuous transfer over the network during use of the ServiceMember information, content, access logs, session informationDatabase hosting and operational supportSame as the retention periods in Section 3
Supabase Inc. — production data centreSeoul region, Republic of Korea (ap-northeast-2)Continuous transfer over the network during use of the ServiceMember information, content, access logsStorage and backup of production dataSame as the retention periods in Section 3
Supabase Inc. — development and testing data centreTokyo region, Japan (ap-northeast-1)Continuous transfer over the network, limited to development and test trafficData processed in the development and test environment (as a rule, actual Member data is stored only in the production environment)Operation of the development and test environmentDevelopment data lifecycle (up to 90 days)

7. Destruction of Personal Data

  1. Where the retention period for personal data has elapsed or the purpose of processing has been achieved, the Company destroys the relevant personal data without delay.
  2. Where a Member requests withdrawal, destruction is carried out only for those items whose statutory retention period under Section 3 has elapsed.
  3. The procedures and methods of destruction are as follows.
    • Procedure: Personal data for which the purpose of processing has been achieved or the retention period has elapsed is moved to a separate database, stored for a certain period in accordance with internal policy and applicable law, and then destroyed.
    • Methods:
      • Electronic files: permanently deleted by an unrecoverable method (deletion of database records plus automatic disposal after the backup disposal cycle)
      • Paper documents: shredded or incinerated

8. Processing of Personal Data of Children Under 14

  1. The Company does not collect personal data of children under 14 years of age. Where it is confirmed at registration that an applicant is under 14, the registration application is refused.
  2. Where the Company becomes aware that it has collected personal data of a child under 14, it immediately deletes that information and cancels the registration.

9. Dormant Account Policy

  1. In accordance with the Network Act and its subordinate regulations, the Company may convert the personal data of Members who have not used the Service for one year to a dormant state and store it separately.
  2. Thirty days before conversion to dormancy, the Company gives prior notice by email of the fact that dormancy processing is scheduled, the scheduled date, and the categories of personal data to be made dormant.
  3. Where a Member wishes to use the Service again after conversion to a dormant state, dormancy may be released after identity verification.
  4. Where non-use continues for a certain period after the dormant state, the Company may destroy the relevant personal data upon prior notice.

10. Rights and Obligations of Data Subjects and How to Exercise Them

  1. Members may exercise the following rights against the Company at any time:
    • Request to access personal data
    • Request for correction where there is an error
    • Request for deletion
    • Request to suspend processing
  2. These rights may be exercised against the Company in writing, by email or by similar means, and the Company will act on them without delay.
  3. The Company notifies the result of processing, or its processing plan, in respect of requests for access, correction, deletion or suspension of processing under a data subject's rights within 10 business days.
  4. Where a data subject requests correction or deletion in respect of an error in personal data, the Company does not use or provide that personal data until the correction or deletion is completed.
  5. Rights may be exercised through an agent, such as the Member's legal representative or a duly authorized person. In that case, a power of attorney in the form of Annex No. 11 to the Public Notice on Methods of Processing Personal Data (Notice No. 2020-7) must be submitted.
  6. Requests to access personal data and to suspend processing may be restricted under Article 35(5) and Article 37(2) of PIPA.
  7. Where personal data is expressly specified as subject to collection under other laws, deletion of that personal data may not be requested.

11. Measures to Ensure the Safety of Personal Data

Pursuant to Article 29 of PIPA, the Company takes the following technical, administrative and physical measures necessary to ensure safety.

11.1 Administrative measures

11.2 Technical measures

11.3 Physical measures

11.4 Incident response

12. Use of Cookies and Similar Technologies

  1. The Company may use cookies and similar technologies (such as local storage) in order to provide users with a personalized service.
  2. Cookies are used for the following purposes:
    • Maintaining login sessions
    • Storing user preferences
    • Service usage statistics
    • Prevention of fraudulent use (enforcing the one-account-one-session policy)
  3. Analytics cookies (Google Analytics): The Company uses Google Analytics (via Google Tag Manager) for service improvement and acquisition-source analysis.
    • Categories collected: pages visited, events (button clicks, plan views, scrolling, etc.), acquisition source (including UTM parameters such as search terms, advertising and social media), device and browser information, approximate location (country, city)
    • Purpose of collection: analysis of Service usage statistics, measurement of marketing channel performance
    • Retention period: up to 14 months (Google Analytics data retention setting)
    • Method of consent: analytics cookies are stored only where "Allow" is selected in the cookie consent banner displayed on first visit. If "Reject" is selected, analytics cookies are not stored and there is no restriction on use of the Service.
    • Withdrawal of consent: deleting the browser's site data (cookies and local storage) resets the consent selection so that it can be made again.
  4. Users may refuse the storage of cookies through their web browser settings; in that case, use of some parts of the Service may be restricted.

13. Personal Information Protection Officer and Contact

The Company designates a Personal Information Protection Officer as set out below, who has overall responsibility for personal data processing and for handling data subjects' complaints and providing remedies in relation to personal data processing.

Personal Information Protection Officer

General enquiries

Reporting and consultation on infringement of data subject rights

Users may apply to the following bodies for dispute resolution or consultation in order to obtain relief for personal data infringement.

14. Changes to This Privacy Policy

  1. This Privacy Policy applies from May 4, 2026.
  2. Where content is added to, deleted from or modified in this Policy, prior notice is given through in-Service announcements at least 7 days before the effective date (at least 30 days in advance where the change is unfavourable to users).

Addendum

This Policy takes effect on May 4, 2026.

Company Information