Privacy Policy

Last updated: [TBD]

1. Operator and Scope of this Policy

DShine (the "Company") processes personal data of QQRR.ME members, sign-up applicants, guest creators, visitors to public links, people who contact us, and participants in the use of forms. This Policy distinguishes processing for purposes determined by the Company from the processing of response data carried out on the instructions of a form owner.

For form questions and responses, also check the notice given by the form owner regarding who is collecting the data, for what purpose, and for how long. After navigating to an external destination, check that site's own policy. An external service's policy does not substitute for the Company's own responsibility.

This Policy is a public notice; reading it is not itself consent to all processing. Processing that relies on consent is presented in a separate notice setting out the purpose, items, period, consequences of refusal, and how to withdraw.

2. Sources, Items, and Purposes of Information

2. Sources, Items, and Purposes of Information
Context and sourceInformation processedPurpose
Email sign-up — the individual and the authentication systemEmail, authentication credentials such as a password, authentication account identifier, authentication status and time, sign-up progress informationSign-up application, authentication, account creation and security
Google sign-up — Google and the authentication systemAuthentication account identifiers, email, authentication result. Additional profile data: [To confirm: reconcile what Supabase Auth receives and stores]The Google sign-in and account linking requested
Account settings — entered by the individualUsername, language, selected plan, referrer and coupon information enteredAccount and address configuration, processing of features and benefits
Link and QR creation — the individual and the systemDestination URL, short code and QR identifier, creation, expiry and status, guest creation permission informationConnection, verification of management rights, expiry and transfer
Link visits and QR scans — the access requestHashed IP, User-Agent, Referer, access time and connection identifierStatistics and service operation. Subject to the review of processing grounds in Section 3
Form building — entered by the ownerQuestions, options and settings, notices and contact details, account and form identifiersPublication and response management
Form responses — entered by the respondentAnswers requested by the owner, submission time, form identifier, hashed IP, transmitted file names and metadataReceipt, storage, and submission processing of responses as a processor
Link in bio — entered by the publisherIntroduction, name, images, contact details, and links the publisher has chosen to make publicProvision of the requested public page. [To confirm: launched features and storage scope]
Enquiries and reports — the individual and the systemEnquiry, reply, report content and evidence, linked account, email provided by the reporter, hashed IP and identifiers of the reporting routeReplies, rights requests, handling of reports, appeals, and disputes
Consent and operational records — choices and operational actionsItems chosen, time, account, hashed IP and browser information, records of operational measuresProcessing of choices, evidence of history, security auditing. Document version: [To confirm: verify what is actually stored]

The password used for email sign-up is processed for authentication purposes through Supabase Auth. The absence of a password column in the QQRR business database does not mean that the service does not process passwords. The Company does not receive Google passwords.

URLs, free-text entries, public introductions, and responses may contain personal data. The absence of a telephone number field in account settings does not mean that the service as a whole never receives telephone numbers or sensitive information.

Application access logs store a hashed value instead of the raw IP address. This is not guaranteed to be fully anonymous information. Network connections necessarily involve processing of raw IP addresses, and providers' raw logs and access records are addressed separately in Section 6.

3. Grounds for Processing and the Distinction of Consent

3. Grounds for Processing and the Distinction of Consent
CategoryHow it applies
Account creation and authentication, management of requested links and formsThe scope necessary for a request made in the course of concluding a contract, or for performing the contract. Advertising and all visitor analytics are not included in this ground
Statutory retention and ordersLimited to the subject matter, purpose, and period required by the relevant law
Use of contact details for advertising purposes, and receipt of advertisingOptional consent for each notified purpose and channel
Minimum usage records after withdrawalSeparate optional consent to answer requests to confirm the Member's own link creation, destination selections or form question configuration. Distinct from mandatory Terms and marketing consent; refusal does not prevent sign-up or service use. Items, periods and withdrawal methods are explained in the additional retention document provided alongside this Policy
The substance of form responsesThe ground obtained by the form owner and the scope of the processing mandate. The owner's consent at sign-up is not the respondent's consent
Visitor statistics, security, abuse prevention, disputes, and preservation of evidence[To confirm: assessment of the minimum items, necessity, and rights impact for each processing activity, and the ground under Article 15 of the Personal Information Protection Act]. "Service improvement" alone is not used to justify all logging
Cross-border transfers, sensitive data, and provision to third partiesThe statutory requirements for that processing — separate notice, consent, or contract — apply

In Korea, performance of a contract under Article 15(1)(4) of the Personal Information Protection Act is distinguished from consent under Article 15(1)(1). In Japan, the specification and prior indication of the purpose of use is distinguished from processing that requires separate consent. A ground for processing in one country is not applied as-is to every other country.

If a purpose changes, the Company reviews the relationship to the original purpose and the applicable law, gives notice, and obtains consent before the change where required. Consent for a new purpose is not obtained merely by revising this Policy.

4. Retention Periods and Destruction

Information is retained for as long as necessary for its purpose and destroyed without delay once it is no longer needed. Information subject to separate statutory retention is stored with the items and grounds distinguished. Hiding from display, irrecoverability, and actual deletion are different things.

4. Retention Periods and Destruction
Information groupRetention and destruction standard
Incomplete sign-up authentication accounts and temporary information[TBD: determination of incompleteness, period, and Auth deletion procedure]
Member accounts and recoverable contentSubject to a recovery request for 90 days after withdrawal. Accounts without a preservation reason become eligible for destruction after the recovery period, with no additional waiting period. Investigation holds and preservation following a confirmed action follow separate criteria. [To confirm: implement the confirmed criteria in code, independently verify them, and approve actual execution]
Minimum usage records covered by optional consentThe notified items among the internal account ID, sign-up and withdrawal dates; link creation time, short link and destination; and form identifier, questions, choices and order are stored separately from receipt of the withdrawal request for the periods shown in the consent document. The recovery period is included; periods are not recalculated on destruction of the originals. If records become unnecessary or consent is withdrawn before the period ends, necessary measures, including destruction, are taken without delay, except where the law provides otherwise. This consent alone does not authorize retention of respondent information, attachments, authentication information, reusable payment methods, third-party personal data, sensitive data or secrets. Setting changes do not retroactively extend past consent or deadlines
Guest creation and permission informationLink lifetime is one year from creation. The period for destroying the URL, token, and records after expiry is [TBD]. Expiry and destruction are different
Click and scan recordsUnder policy, statistics are retained for Free 3 months / Starter 6 months / Pro 24 months / Business 60 months. [To confirm: the distinction between raw and aggregated data, the start date, truncation calculation, actual destruction, and handling on plan changes]
Form responsesThe purpose and period stated by the owner on the form. [To confirm: end of the processing mandate, deletion by the owner, account termination, backup arrangements, and actual behaviour]
Public introductions and contentProvision ceases on deletion or discontinuation of the feature. Residual periods, image copies, and backups are [To confirm: actual storage and destruction]
Records of enquiries, reports, cancellations, and measuresFive years under internal policy. Not every item is a statutory obligation. [To confirm: start date, minimum scope, and ground for each record]. This is not approval to publish a blanket five-year retention
Email addresses used for advertisingUntil consent to the use of personal data for advertising purposes or consent to receive advertising is withdrawn, or the member withdraws, whichever occurs first. Evidence records are kept separately from the sending list. [To confirm: actual exclusion from sending and destruction]
Evidence of advertising consent and withdrawalFive years after the last advertising message under internal policy. [To confirm: start date for those never sent to, actual destruction, and evidence requirements by jurisdiction]
General consent recordsFive years under internal policy. [To confirm: ground, start date, minimum evidence, and actual destruction for each type of consent]. Marketing consent and optional additional retention consent evidence are excluded from this standard. Additional retention consent evidence is kept only while needed to process the current signup's choice or substantiate actual additional records, and is cleared when consent is withdrawn or the last additional record for a closed signup is deleted
Administrator audit logsThree years under internal policy. [To confirm: which items contain personal data, the ground for retention, the start date, and actual destruction]
Notification recordsOne year under internal policy, regardless of read status. [To confirm: ground for retention, start date, and actual destruction by notification type]
Statutory records of launched transactionsDisplays and advertising 6 months; contracts, withdrawal of subscription, payment and supply 5 years; consumer complaints and disputes 3 years. Stored separately according to the record concerned and the applicable law

The Company identifies the information to be destroyed and deletes electronic information so that it cannot be recovered or reconstructed. Any paper records are destroyed by shredding or a similar method. Deletion in the authentication system, at processors, and in backups is also subject to verification. [To confirm: actual destruction cycle, separation and access restriction, backup expiry, and re-application of deletion after a restore].

Where there is a statutory preservation order or a lawful ground for preserving evidence, deletion may be suspended to the extent necessary. An account is not retained indefinitely merely because of a vague possibility of future dispute or the fact that a report has been received.

5. Provision to Third Parties and Public Disclosure

Personal data is provided to third parties only where permitted by law or where there is another lawful ground such as separate consent. Where a necessary provision arises, the Company will notify at that time the recipient, purpose, items, period, and the consequences of refusal. Processors are distinguished from third parties who use data for their own independent purposes.

Contact details, introductions, and images published through Link in bio, and form screens, may be viewed and copied by visitors. Form responses differ from the public question screen; who may view them and how they may be exported follow the owner's settings and contractual scope.

[To confirm: the current list of third-party provisions, independent processing by payment providers, and transfers to analytics or advertising tools]. Until this is confirmed, the Company will not state definitively that there is "no provision to third parties" or "no sale or sharing".

6. Processing Mandates and Cross-Border Transfers

Where processing is entrusted, the Company reflects in the contract restrictions on processing beyond the purpose, access controls, protective measures, sub-processing, and deletion on termination, and manages the processor. The country of a provider's head office and the country to which data is actually transferred may differ. Even where data is stored domestically, access by overseas support staff, sub-processing, and backups are verified separately.

The following table is to be finalized by contract and configuration, provider by provider. Unverified countries are not replaced with "worldwide".

6. Processing Mandates and Cross-Border Transfers
Provider and functionContracting entity and contactItems and purposeCountry, timing, and methodRetention and transfer ground
Supabase — authentication and database[To confirm]Authentication and service data. Confirm the scope of Auth, DB, and Storage[To confirm: countries of storage, support, and backup, and the request and synchronization methods][To confirm: contract, deletion, and the route applicable in Korea and Japan]
Vercel — web hosting[To confirm]The actual items in web requests and logs[To confirm: countries and timing for functions, logs, and support][To confirm: retention and ground]
Railway — API hosting[To confirm]The actual items in API requests and server logs[To confirm: countries and timing for the service, logs, and support][To confirm: retention and ground]
Cloudflare — network[To confirm]The actual items processed by the DNS, proxy, and security features in use[To confirm: whether the proxy is enabled, and the countries of processing and support][To confirm: retention and ground]
Resend — email[To confirm: actual use, sending, and contract]Sender and recipient email addresses, subject, body, and sending logs[To confirm: countries and timing for transmission, logs, and support][To confirm: retention and ground]

Each row must be finalized down to the exact name of the contracting entity and its personal data contact, the items transferred, the country, the timing and method, the purpose, the retention period, and the method and effect of refusal. Processing mandates and storage necessary for performance of the contract, provisions requiring separate consent, and other permitted routes are distinguished. Required information is disclosed or notified before transfer, and separate consent is obtained where required.

Where Japan's consent-based provision to a foreign third party applies, the Company also explains the data protection regime of the destination country and the recipient's protective measures. Where reliance is placed on an equivalent-measures framework, the Company carries out continuing verification and provides information on request. Not having investigated a country yet does not mean that the exception for an unidentifiable country has been satisfied.

For Google sign-in and payment providers, the Company will verify and disclose whether the relationship is one of independent processing or a processing mandate. Toss Payments and Lemon Squeezy, which are not yet in use, are not presented as processors already receiving personal data.

7. Cookies, Browser Storage, and Tracking

Cookies or browser storage may be used for authentication state, selected settings, guest creation results, and editing previews. These can be deleted or blocked in the browser, but doing so may affect staying signed in or managing guest results.

7. Cookies, Browser Storage, and Tracking
Storage or trackingPurposePeriod and refusal
Authentication cookies and sessionsMaintaining sign-in and authentication[To confirm: name, party, scope, and expiry]. Sign out, or delete or block in the browser
Guest link storageDisplaying creation results, permission tokens, and expiry information[To confirm: conditions for removal]. Clear site data. Hiding and deletion are different
Preview and settings storageRetaining editing previews and selections[To confirm: storage, expiry, and removal behaviour for each item]
Cross-site tracking and analytics by third parties[To confirm: audit of SDKs and network calls][To confirm: use, refusal, and handling of signals]

Do Not Track handling: [To confirm: actual browser and server behaviour]. Application and handling of statutory opt-out signals such as Global Privacy Control: [To confirm: jurisdictional assessment and implementation]. The two signals are not presented as equivalent. If non-essential storage or tracking requiring consent is introduced, a separate means of choice will be provided before it operates.

8. The Roles of Form Owners and the Company

The form owner determines the purpose, items, period, and lawful ground for collecting responses. The Company supports storage, retrieval, export, and deletion within the scope of the processing mandate, as set out in the addendum. The Company does not take the position that it "bears no responsibility because it is a platform" or that "all response data belongs to the Company".

Requests to access or delete the substance of responses may be made to the form owner's contact point. Where the owner cannot be reached, or where the request concerns the Company's own processing, the contact point in Section 11 may be used. The Company performs its own statutory obligations and cooperates with the owner on requests falling within the processing mandate.

9. Rights of Users and Legal Representatives

Users may request access and a copy, correction, deletion, suspension of processing, and withdrawal of consent, in accordance with applicable law. A legal representative or other duly authorized agent may also exercise these rights. The Company processes requests after minimum verification of identity or authority, and explains any grounds for limitation or refusal together with the appeal and remedy procedures.

Where a request cannot be fully performed because of statutory retention or the protection of others' rights, the Company explains the scope and the ground. Cessation of processing after withdrawal is distinguished from the retention of the minimum evidence required by law. Users will not be unfairly discriminated against for exercising their rights. Where a fee permitted by law is actually charged, the ground and amount are explained in advance.

9. Rights of Users and Legal Representatives
RegionAdditional information
KoreaRights of access, correction, deletion, suspension of processing, and withdrawal under the Personal Information Protection Act, and other rights where the requirements are met. Remedies are available through the Personal Information Protection Commission, the Personal Information Dispute Mediation Committee, and the Privacy Infringement Report Centre
JapanDisclosure of retained personal data and of records of provision to third parties, and correction, suspension of use, deletion, and suspension of provision under the APPI, subject to the applicable requirements and exceptions. Requests for information on equivalent measures for cross-border transfers may also be submitted to the Company's contact point
United StatesAccess, deletion, correction, a portable copy, opt-out of certain processing, and appeal rights vary according to the requirements applicable in each state. [To confirm: the states applicable to QQRR, the rights, deadlines, and request channels]
CaliforniaWhether the CCPA applies is [To confirm: business status, revenue, purchase/sale/sharing, and contractual relationships]. If it applies, the actual processing categories and the corresponding means of opting out of sale or sharing and of limiting the use of sensitive information will be added. An unconfirmed status is not to be read as "no rights"

10. Children, Safeguards, and Incident Response

Membership is not offered to persons under the age of 14. This statement alone does not guarantee that no children's data is ever processed. If the Company becomes aware that children's data is contained in an account, form, or enquiry, it will consider the measures required by applicable law, including ceasing processing, deletion, and contacting a guardian. Separate requirements, such as those for children under 13 in the United States, are also taken into account.

The Company implements the necessary measures for access control, protection of authentication credentials, protection in transit, processing records, and management of providers. [To confirm: state only the measures actually in operation, and do not present a provider's certification as the Company's own certification]. If an incident occurs, the Company will notify users, report to the authorities, and mitigate harm in accordance with the requirements and deadlines of applicable law.

11. Officer in Charge, Contact, and Changes

11. Officer in Charge, Contact, and Changes
ItemDetails
Operator / RepresentativeDShine / Lee Jinhyeok
Personal data protection officerLee Jinhyeok
Address302-S411, 7 Yonggu-daero 2790beon-gil, Suji-gu, Yongin-si, Gyeonggi-do 16866, Republic of Korea
Emailservice@qqrr.me — [To confirm: whether it is actually monitored and capable of identity verification and processing]
Telephone[To confirm: contact number to be published]
Online requests[To confirm: an actual request URL usable by non-members]

Material changes to processing are published so that the content and effective date can be readily identified, together with any individual notice or consent that is required. A history is provided showing previous policies and their respective effective dates.

Effective date: [TBD]. Document version: [TBD]. Previous policy: [To confirm: URL of the publication history].

Loading the current retention document…