Roastive Privacy Policy
Reference translation. This English text is provided for convenience only. The Korean version at
/privacyis the authoritative original; in the event of any discrepancy in interpretation, the Korean version prevails.
- Effective date: May 4, 2026 (delegated issuance of electronic tax invoices added: June 20, 2026 / Partner Roaster application items added and change of payment service provider reflected: August 19, 2026 / employee health examination certificates (sensitive data) and related safeguards added: September 29, 2026)
- Last amended: September 22, 2026
- Governing language: Korean
STANDARD SQUARE COFFEELAB (the "Company") complies with the personal data protection provisions of applicable laws, including the Personal Information Protection Act ("PIPA") and the Act on Promotion of Information and Communications Network Utilization and Information Protection, and establishes and discloses this Privacy Policy as follows in order to protect users' personal data.
1. Categories of Personal Data Processed
The Company collects and uses the following categories of personal data in order to provide the Service.
1.1 On registration (required)
- Email address
- Password (stored as a one-way hash)
- Name or nickname
- Mobile phone number (optional, where notifications are received)
1.2 When operating a Roastery (workspace)
- Roastery (store) name, place-of-business address
- Business registration number (only where tax invoices are issued; optional)
- Representative's name
- Email addresses and permission information of additional users invited to the Roastery
1.3 When paying for Paid Services
- Payment method information (partial card identifier — retained only in the form of a tokenized Billing Key; the full card number is retained by the payment service provider)
- Payment amount and transaction date and time
- Business information for VAT filing and tax invoice issuance (optional)
1.4 Information collected automatically during use of the Service
- Access logs (access date and time, IP address)
- Cookies and session information
- Device information (OS, browser type and version, screen resolution)
- Service usage records (menu use, feature use, error logs)
- Information for concurrent session management (session ID, device label, IP, User-Agent — for the purpose of enforcing the one-account-one-session policy)
1.5 Content entered into the Service by Members
- Data entered directly by Members, such as roasting profiles, inventory information, order information and customer information
1.6 When applying to the Partner Roaster programme
Where a person applies to the Partner Roaster recruitment programme operated by the Company, the following items are collected regardless of whether that person is a Member.
Required items
- Representative's name, trade name (roastery name)
- Email address, contact number
- Location of the place of business
- Photograph of the roasting machine
- Roaster manufacturer and model name
- PLC communication method
- Weekly roasting frequency, monthly production volume
- Roasting software currently in use
Optional items
- Instagram account
- Free-text content such as motivation for applying
An application may be submitted without completing the optional items, and the Company does not refuse to accept an application on the ground that they were not completed.
Photographs of roasting machines that are submitted are used solely for the purpose of confirming the roaster model and installation environment, and are not disclosed or used for marketing outside the purpose of review. Where separate use is required, individual consent is obtained in advance.
1.7 Employee health examination certificates (sensitive personal data) entered by Members
To manage the employee health examination obligation under Article 40 of the Food Sanitation Act and Article 49 of its Enforcement Rule, a Member (Roastery) may register the following information about its employees in the "Employee Health Certificates" feature of the Service.
- Employee name, position and contact number (optional)
- The health examination certificate file, its issue date and expiry date
- The date and time at which the Member confirmed the employee's separate consent to the collection and use of the sensitive data
A health examination certificate constitutes sensitive personal data (health information) under Article 23 of PIPA. The controller of this data is the Member (Roastery) that employs the person; the Company processes it solely as a processor entrusted by the Member with storage and management under Article 26 of PIPA. Before registering, the Member must obtain the employee's separate consent to the collection and use of the sensitive data, and the Company permits registration only after the Member records that confirmation. The Company does not use this data for any purpose other than the entrusted work (storage, controlled viewing and expiry reminders), does not provide it to third parties, and excludes it from automated text recognition (OCR) and other external AI processing.
2. Purposes of Processing Personal Data
The Company processes collected personal data for the following purposes, and obtains prior consent where the purpose of processing changes.
| Purpose | Categories processed |
|---|---|
| Member management (confirming intent to register, identification and authentication, prevention of unauthorized use) | Email, password, name |
| Service provision (roastery, profile, inventory and order management) | Content entered by Members, Roastery information |
| Payment and settlement for Paid Services | Payment method, transaction history, business information |
| Tax invoice issuance and accounting | Business registration number, representative's name |
| Customer support and complaint handling | Email, mobile phone number, enquiry content |
| Security (prevention of fraudulent use, concurrent session limit, incident response) | Access logs, IP, session information |
| Fulfilment of statutory obligations (Electronic Commerce Act, Value-Added Tax Act, etc.) | Transaction and payment records |
| Statistical analysis for service improvement | Automatically collected information (after pseudonymization or anonymization) |
| Operation of the Partner Roaster programme (receipt of applications, review of eligibility and roaster compatibility, notification of selection results) | Items collected under Section 1.6 |
| Supporting the Member's (Roastery's) management of employee health examination obligations — limited to the entrusted storage, controlled viewing and expiry reminders | Items in Article 1.7 (including sensitive data) |
3. Retention and Use Period of Personal Data
-
The Company retains and uses a Member's personal data from the time of registration until the Member withdraws.
-
However, in the following cases, data is retained for the periods specified even after withdrawal.
Category Retention period Legal basis Records on contracts or withdrawal of subscription 5 years Act on Consumer Protection in Electronic Commerce Records on payment and supply of goods 5 years Act on Consumer Protection in Electronic Commerce Records on consumer complaints or dispute handling 3 years Act on Consumer Protection in Electronic Commerce VAT-related records (tax invoices, etc.) 5 years Value-Added Tax Act Records on labelling and advertising 6 months Act on Consumer Protection in Electronic Commerce Records on collection, processing and use of credit information 3 years Credit Information Use and Protection Act Access records under the Protection of Communications Secrets Act 3 months Protection of Communications Secrets Act Records on fraudulent use 1 year Prevention of fraudulent use -
Content entered into the Service by a Member (roasting profiles and the like) is destroyed immediately upon withdrawal or within a reasonable period thereafter. The handling of content shared with other Members is subject to separate guidance.
-
Partner Roaster application information collected under Section 1.6 (including submitted photographs) is destroyed within 90 days from the time notification of the selection results for that recruitment round is completed. Where an applicant is selected and converts to Member status, the items necessary for provision of the Service are retained under Paragraph 1.
-
Employee health examination certificates under Article 1.7 (sensitive data) are destroyed — the original file and its registration record — as soon as the Member deletes the employee or destroys the document in the Service, and upon the Member's withdrawal in accordance with the preceding paragraphs. Access records of viewing, registration and destruction are, however, retained for two years pursuant to Article 8 of the Standards for Measures to Ensure the Safety of Personal Information and then destroyed.
4. Provision of Personal Data to Third Parties
-
The Company does not provide a data subject's personal data to third parties except where Articles 17 and 18 of PIPA apply, such as where separate consent has been obtained from the data subject or where there is a special provision of law.
-
In the following cases, personal data may be provided to third parties on a statutory basis or with the Member's consent.
Recipient Purpose of provision Categories provided Retention period Judicial and investigative authorities Where there is a lawful request under applicable law Categories prescribed by law Period prescribed by law Counterparty to a dispute For resolution of a dispute between Members, with the Member's consent Minimum information relating to the dispute Until the dispute concludes -
Transfers of personal data to the payment service provider and cloud infrastructure operators are governed by Section 5 (Outsourcing of Personal Data Processing) and Section 6 (Cross-border Transfer of Personal Data) of this Policy.
5. Outsourcing of Personal Data Processing
In order to provide a smooth and improved Service, the Company outsources personal data processing tasks as follows. When outsourcing, the Company specifies obligations for safe processing through outsourcing agreements pursuant to Article 26 of PIPA.
| Processor | Outsourced task | Categories outsourced |
|---|---|---|
| Supabase Inc. (incorporated in the United States; data centres in Seoul, Korea / Tokyo, Japan — see Section 6 of this Policy) | Operation of database, authentication, storage and serverless functions | Member information, content entered by Members, access logs, session information |
| Toss Payments Co., Ltd. | Credit card payment processing, Billing Key issuance and recurring billing, payment history management | Card issuer and partial card number, Billing Key, payment amount and date/time, Member identifier |
| Supabase Inc. | Sending authentication-related emails such as registration and password reset (Supabase Auth) | Email address, name |
| Linkhub Co., Ltd. (Popbill) | Delegated issuance of electronic tax invoices (Article 69 of the Enforcement Decree of the Value-Added Tax Act), transmission to the National Tax Service, retention of issuance history, processing of emails sent to purchasers | Member's (supplier's) business registration number, trade name, representative's name, place-of-business address, business type and item, email; purchaser's (recipient's) business registration number, trade name, representative's name, email; transaction amount |
| Google LLC (Google Analytics — United States; see Section 6 of this Policy) | Analysis of website visit and usage statistics (only where analytics cookies are consented to) | Pages visited, events (button clicks, scrolling, etc.), acquisition source (including UTM), device and browser information, approximate location (country, city), cookie IDs of an advertising-identifier nature (directly identifying information such as name or email is not collected) |
When concluding outsourcing agreements, the Company specifies the following matters pursuant to Article 26 of PIPA.
- Prohibition of processing personal data beyond the purpose of performing the outsourced task
- Technical and administrative protective measures for personal data
- Measures to ensure safety, such as restrictions on sub-outsourcing and restrictions on access to personal data
- The purpose and scope of the outsourced task, and matters concerning liability including damages
Where a processor changes or the content of an outsourced task changes, the Company discloses this through this Policy.
6. Cross-border Transfer of Personal Data
For the operation of the Service, certain personal data may be transferred abroad as follows.
| Recipient | Country of transfer | Date and method of transfer | Categories transferred | Purpose of transfer | Retention and use period |
|---|---|---|---|---|---|
| Supabase Inc. (operating entity) | Operational support: United States and others | Continuous transfer over the network during use of the Service | Member information, content, access logs, session information | Database hosting and operational support | Same as the retention periods in Section 3 |
| Supabase Inc. — production data centre | Seoul region, Republic of Korea (ap-northeast-2) | Continuous transfer over the network during use of the Service | Member information, content, access logs | Storage and backup of production data | Same as the retention periods in Section 3 |
| Supabase Inc. — development and testing data centre | Tokyo region, Japan (ap-northeast-1) | Continuous transfer over the network, limited to development and test traffic | Data processed in the development and test environment (as a rule, actual Member data is stored only in the production environment) | Operation of the development and test environment | Development data lifecycle (up to 90 days) |
- Method of transfer: Encrypted transmission over the information and communications network (TLS 1.2 or higher)
- How to refuse transfer: Consent to transfer may be refused at the registration stage; in that case, use of the Service may be restricted.
- Because the Company uses the Tokyo region only for its development environment, production data (actual Members' payment information, content and the like) is, as a rule, stored in the Seoul region. Where the Tokyo region is temporarily used out of operational necessity, prior notice or separate consent is obtained.
- Google LLC (Google Analytics) is located in the United States, and visit and usage statistics for users who have consented to analytics cookies may be transferred to the United States over the network. The categories and purposes of transfer follow the outsourcing table in Section 5, and the retention period is up to 14 months (Google Analytics data retention setting). If "Reject" is selected in the cookie consent banner, no transfer occurs.
- Toss Payments Co., Ltd. is a business operator located within the Republic of Korea, and data processing under this outsourcing arrangement takes place domestically.
7. Destruction of Personal Data
- Where the retention period for personal data has elapsed or the purpose of processing has been achieved, the Company destroys the relevant personal data without delay.
- Where a Member requests withdrawal, destruction is carried out only for those items whose statutory retention period under Section 3 has elapsed.
- The procedures and methods of destruction are as follows.
- Procedure: Personal data for which the purpose of processing has been achieved or the retention period has elapsed is moved to a separate database, stored for a certain period in accordance with internal policy and applicable law, and then destroyed.
- Methods:
- Electronic files: permanently deleted by an unrecoverable method (deletion of database records plus automatic disposal after the backup disposal cycle)
- Paper documents: shredded or incinerated
8. Processing of Personal Data of Children Under 14
- The Company does not collect personal data of children under 14 years of age. Where it is confirmed at registration that an applicant is under 14, the registration application is refused.
- Where the Company becomes aware that it has collected personal data of a child under 14, it immediately deletes that information and cancels the registration.
9. Dormant Account Policy
- In accordance with the Network Act and its subordinate regulations, the Company may convert the personal data of Members who have not used the Service for one year to a dormant state and store it separately.
- Thirty days before conversion to dormancy, the Company gives prior notice by email of the fact that dormancy processing is scheduled, the scheduled date, and the categories of personal data to be made dormant.
- Where a Member wishes to use the Service again after conversion to a dormant state, dormancy may be released after identity verification.
- Where non-use continues for a certain period after the dormant state, the Company may destroy the relevant personal data upon prior notice.
10. Rights and Obligations of Data Subjects and How to Exercise Them
- Members may exercise the following rights against the Company at any time:
- Request to access personal data
- Request for correction where there is an error
- Request for deletion
- Request to suspend processing
- These rights may be exercised against the Company in writing, by email or by similar means, and the Company will act on them without delay.
- The Company notifies the result of processing, or its processing plan, in respect of requests for access, correction, deletion or suspension of processing under a data subject's rights within 10 business days.
- Where a data subject requests correction or deletion in respect of an error in personal data, the Company does not use or provide that personal data until the correction or deletion is completed.
- Rights may be exercised through an agent, such as the Member's legal representative or a duly authorized person. In that case, a power of attorney in the form of Annex No. 11 to the Public Notice on Methods of Processing Personal Data (Notice No. 2020-7) must be submitted.
- Requests to access personal data and to suspend processing may be restricted under Article 35(5) and Article 37(2) of PIPA.
- Where personal data is expressly specified as subject to collection under other laws, deletion of that personal data may not be requested.
11. Measures to Ensure the Safety of Personal Data
Pursuant to Article 29 of PIPA, the Company takes the following technical, administrative and physical measures necessary to ensure safety.
11.1 Administrative measures
- Establishment and implementation of an internal management plan
- Minimization of personnel handling personal data, and periodic training
- Differentiated grant of access privileges to personal data, and periodic review
- Periodic review of processors and contract management
11.2 Technical measures
- One-way hash storage of passwords
- Encryption of personal data in transit (TLS 1.2 or higher)
- Encryption of database storage where applicable
- Operation of access control systems (IP-based, RLS policies and the like)
- Retention of access records and prevention of forgery or alteration
- Prevention of malicious code through installation of anti-virus software
- Minimization of session hijacking risk through the one-account-one-session policy
- Restriction of access to sensitive data (employee health examination certificates) to the Roastery admin and manager roles (row-level security policies and private storage)
- Application-layer encryption of sensitive data files at rest (per-file AES-256-GCM envelope encryption; the key-encryption key is held only on the service server), and automatic destruction or anonymisation of access records and inactive employee records once their retention period has elapsed
- Two-year retention of access records (time, actor, IP address and action) for viewing, registering and destroying sensitive data
- Short-lived (5-minute) links for viewing sensitive data
- Exclusion of sensitive data files from automated text recognition (OCR) and other external AI processing
11.3 Physical measures
- Reliance on the physical security measures of cloud infrastructure providers (Supabase / hosting data centres)
- Office access control and security of document storage facilities
11.4 Incident response
- Prompt reporting and notification in accordance with PIPA and other applicable laws in the event of a personal data breach
12. Use of Cookies and Similar Technologies
- The Company may use cookies and similar technologies (such as local storage) in order to provide users with a personalized service.
- Cookies are used for the following purposes:
- Maintaining login sessions
- Storing user preferences
- Service usage statistics
- Prevention of fraudulent use (enforcing the one-account-one-session policy)
- Analytics cookies (Google Analytics): The Company uses Google Analytics (via Google Tag Manager) for service improvement and acquisition-source analysis.
- Categories collected: pages visited, events (button clicks, plan views, scrolling, etc.), acquisition source (including UTM parameters such as search terms, advertising and social media), device and browser information, approximate location (country, city)
- Purpose of collection: analysis of Service usage statistics, measurement of marketing channel performance
- Retention period: up to 14 months (Google Analytics data retention setting)
- Method of consent: analytics cookies are stored only where "Allow" is selected in the cookie consent banner displayed on first visit. If "Reject" is selected, analytics cookies are not stored and there is no restriction on use of the Service.
- Withdrawal of consent: deleting the browser's site data (cookies and local storage) resets the consent selection so that it can be made again.
- Users may refuse the storage of cookies through their web browser settings; in that case, use of some parts of the Service may be restricted.
13. Personal Information Protection Officer and Contact
The Company designates a Personal Information Protection Officer as set out below, who has overall responsibility for personal data processing and for handling data subjects' complaints and providing remedies in relation to personal data processing.
Personal Information Protection Officer
- Name: BAE GIHYUN
- Position: Representative
- Email: roastive@kakao.com
General enquiries
- Email: roastive@kakao.com
- Response SLA: first response within 5 business days
Reporting and consultation on infringement of data subject rights
Users may apply to the following bodies for dispute resolution or consultation in order to obtain relief for personal data infringement.
- Personal Information Infringement Report Centre (privacy.kisa.or.kr / ☎ 118)
- Personal Information Dispute Mediation Committee (kopico.go.kr / ☎ 1833-6972)
- Cybercrime Investigation Division, Supreme Prosecutors' Office (spo.go.kr / ☎ +82 2-3480-3573)
- Cyber Bureau, National Police Agency (cyberbureau.police.go.kr / ☎ 182)
14. Changes to This Privacy Policy
- This Privacy Policy applies from May 4, 2026.
- Where content is added to, deleted from or modified in this Policy, prior notice is given through in-Service announcements at least 7 days before the effective date (at least 30 days in advance where the change is unfavourable to users).
Addendum
This Policy takes effect on May 4, 2026.
Company Information
- Trade name: STANDARD SQUARE COFFEELAB
- Representative: BAE GIHYUN
- Business registration number: 567-48-00956
- Place of business: 583 Neungheodae-ro, Namdong-gu, Incheon, Republic of Korea
- Telephone: +82 10-4681-5508
- Mail-order business report number: 2026-Incheon Namdong-gu-0933
- Customer support: roastive@kakao.com
- Website: https://roastive.io