Privacy Policy
Last updated: September 1, 2026 (effective September 8, 2026)
Article 1 (Items and Methods of Collection)
1. Collected directly at registration
- Required: Email, password, company name, contact name
- Optional: Phone number, business type (export/import/both)
Collection method: Direct input through the registration form
2. Collected automatically during use of the Service
IP address, browser and device information, access time, service usage records, and cookies. See Article 7 for details.
3. Business contact information collected in the course of sales activities
- Items: Name, job title, department, company name, phone number, email, address
- Source: Business cards received in person, by mail, or by similar means
- Purpose: Maintaining the business relationship and work-related communication
- Retention: Three years from the end of the business relationship or the last contact
The Company does not collect information beyond what is provided on the business card, and obtains separate consent before using such information to send advertising communications.
Article 2 (Purpose of Collection and Use)
- User identification and registration verification
- Service provision and access management
- Matching service connections and communication
- Customer inquiry response and complaint handling
- Statistical analysis for service improvement (de-identified)
Article 3 (Retention Period)
- Personal information is retained until account deletion and destroyed without delay upon withdrawal.
- However, information may be retained as required by law:
- Records of contracts or subscription withdrawal: 5 years
- Records of payment and supply of goods: 5 years
- Records of consumer complaints or dispute resolution: 3 years
Article 4 (Third-Party Disclosure)
- When the user has given prior consent
- When required by law
- When providing minimum necessary information (company name, contact) for matching services
Article 5 (Processing Delegation)
The Company delegates personal information processing tasks as follows.
| Delegate | Delegated tasks | Retention period |
|---|---|---|
| Supabase Inc. | Member data storage and authentication | Until termination of the delegation agreement |
| Vercel Inc. | Website hosting and content delivery | Until termination of the delegation agreement |
| Resend, Inc. | Notification and newsletter email delivery | Until termination of the delegation agreement |
| Functional Software, Inc. (Sentry) | Error tracking and service reliability | Until termination of the delegation agreement |
| Upstash, Inc. | Request rate limiting (abuse prevention) | Until termination of the delegation agreement |
| Google LLC | Business card recognition, meeting transcription and summary, document analysis, usage analytics | Until termination of the delegation agreement |
| Anthropic PBC | AI analysis response generation | Until termination of the delegation agreement |
The Company specifies safeguards for personal information in its delegation agreements and discloses any change of delegate through this Policy. All delegates listed above are located outside the Republic of Korea; overseas transfer details are set out separately in Article 6.
Article 6 (Overseas Transfer of Personal Information)
Pursuant to Article 28-8(1)3 of the Personal Information Protection Act of Korea (delegation or storage necessary to enter into and perform a contract with the data subject), the Company discloses the matters required under Article 28-8(2) as follows and transfers personal information overseas.
| Recipient | Country | Items transferred | Purpose | Retention period |
|---|---|---|---|---|
| Supabase Inc. | USA | Email, password (stored encrypted), company name, contact name, phone number, service usage records | Member data storage and authentication | Until account deletion |
| Vercel Inc. | USA | IP address, browser and device information, access time | Website hosting and content delivery | Up to 30 days |
| Resend, Inc. | USA | Email address, name, delivery records | Notification and newsletter email delivery | 30 days from delivery |
| Functional Software, Inc. (Sentry) | USA | IP address, request path and user identifier at the time of an error | Error tracking and service reliability | 90 days |
| Upstash, Inc. | USA | IP address | Request rate limiting (abuse prevention) | Up to 24 hours |
| Google LLC (Gemini API) | USA | Business card images uploaded by the user and the name, title and contact details extracted from them; meeting audio and its transcripts; documents submitted for analysis | Business card recognition, meeting transcription/translation/summary, trade document analysis | See the note below |
| Google LLC (Google Analytics) | USA | Cookie identifiers, IP address, page view records | Service usage analytics | Up to 14 months |
| Anthropic PBC | USA | Analysis request text entered by the user | AI analysis response generation | Not retained after processing |
Time and method of transfer: Transfers occur whenever the user uses the relevant feature, over an encrypted network connection (HTTPS).
Note on business card recognition, meeting records and document analysis: These features currently use the free tier of the Google Gemini API. Under Google's terms, content submitted to the free tier and the responses generated may be used to provide, improve and develop Google products and services, and may be reviewed for quality purposes. Please therefore avoid entering sensitive or confidential material into these features. If you do not wish this transfer to occur, simply do not use these features.
How to refuse the overseas transfer and the effect of refusal: Users may refuse the overseas transfer of their personal information.
- To refuse the transfer of member information (Supabase and Vercel), request account deletion. In that case services requiring registration will no longer be available.
- Transfers tied to individual features (Google Gemini, Anthropic, Resend) may be refused by not using the feature or by unsubscribing. Only that feature is restricted; the rest of the Service is unaffected.
- Google Analytics may be refused through your browser's cookie settings or the opt-out add-on provided by Google (tools.google.com/dlpage/gaoptout).
Article 7 (Cookies and Other Automatic Collection Tools)
- The Company uses cookies to provide a tailored service and to analyse how the Service is used. A cookie is a small piece of information sent by a website to your browser and stored on your device.
- Purposes: Maintaining login sessions, remembering language preference, and service usage analytics (Google Analytics 4)
- How to refuse: You may refuse cookie storage through your browser settings (Chrome: Settings > Privacy and security > Third-party cookies / Edge: Settings > Cookies and site permissions / Safari: Preferences > Privacy). Collection by Google Analytics can also be refused using the opt-out add-on provided by Google (tools.google.com/dlpage/gaoptout).
- If you refuse cookie storage, some services that require login may be restricted.
Article 8 (User Rights)
- Users may view or modify their personal information at any time.
- Users may request cessation of processing by withdrawing their account.
- For privacy-related inquiries, please contact the officer below.
Article 9 (Destruction of Information)
- Information is destroyed without delay when the retention period expires or the purpose is achieved.
- Electronic files: Deleted by irreversible methods
- Paper documents: Shredded or incinerated
Article 10 (Security Measures)
The Company maintains the following measures to keep personal information secure.
- Administrative: Minimising the number of personnel who handle personal information, access rights management, and periodic review of those rights
- Technical: One-way encryption of passwords, encryption in transit (HTTPS), row-level access control at the database layer, and audit logging of administrative changes
- Physical: Access control over documents and storage media
Article 11 (Privacy Officer and Access Requests)
The Company designates the following Privacy Officer to oversee personal information processing and to handle inquiries, complaints and remedies from data subjects. Requests to access personal information are also received at the contact details below.
- Privacy Officer: James Lee (CEO)
- Email: james@tylogistics.co.kr
- Phone: 02-6914-9365
Article 12 (Remedies for Infringement of Rights)
Data subjects may apply to the following bodies in Korea for dispute resolution or consultation regarding infringement of their personal information rights.
- Personal Information Dispute Mediation Committee: +82-1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Centre: +82-118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office, Cyber Investigation Division: +82-1301 (www.spo.go.kr)
- National Police Agency, Cyber Bureau: +82-182 (ecrm.police.go.kr)
Supplementary Provisions
- This Privacy Policy is effective from September 8, 2026.
- The previous Privacy Policy (effective April 2, 2026) applied until September 7, 2026.
- Summary of changes: Article 6 (overseas transfer of personal information) and Article 7 (cookies and other automatic collection tools) were newly added, and the delegation table (Article 5), collection of business contact information (Article 1), security measures (Article 10) and remedies for infringement of rights (Article 12) were expanded.
