Privacy Policy
Last updated: [TBD]
1. Operator and Scope of this Policy
DShine (the "Company") processes personal data of QQRR.ME members, sign-up applicants, guest creators, visitors to public links, people who contact us, and participants in the use of forms. This Policy distinguishes processing for purposes determined by the Company from the processing of response data carried out on the instructions of a form owner.
For form questions and responses, also check the notice given by the form owner regarding who is collecting the data, for what purpose, and for how long. After navigating to an external destination, check that site's own policy. An external service's policy does not substitute for the Company's own responsibility.
This Policy is a public notice; reading it is not itself consent to all processing. Processing that relies on consent is presented in a separate notice setting out the purpose, items, period, consequences of refusal, and how to withdraw.
2. Sources, Items, and Purposes of Information
| Context and source | Information processed | Purpose |
|---|---|---|
| Email sign-up — the individual and the authentication system | Email, authentication credentials such as a password, authentication account identifier, authentication status and time, sign-up progress information | Sign-up application, authentication, account creation and security |
| Google sign-up — Google and the authentication system | Authentication account identifiers, email, authentication result. Additional profile data: [To confirm: reconcile what Supabase Auth receives and stores] | The Google sign-in and account linking requested |
| Account settings — entered by the individual | Username, language, selected plan, referrer and coupon information entered | Account and address configuration, processing of features and benefits |
| Link and QR creation — the individual and the system | Destination URL, short code and QR identifier, creation, expiry and status, guest creation permission information | Connection, verification of management rights, expiry and transfer |
| Link visits and QR scans — the access request | Hashed IP, User-Agent, Referer, access time and connection identifier | Statistics and service operation. Subject to the review of processing grounds in Section 3 |
| Form building — entered by the owner | Questions, options and settings, notices and contact details, account and form identifiers | Publication and response management |
| Form responses — entered by the respondent | Answers requested by the owner, submission time, form identifier, hashed IP, transmitted file names and metadata | Receipt, storage, and submission processing of responses as a processor |
| Link in bio — entered by the publisher | Introduction, name, images, contact details, and links the publisher has chosen to make public | Provision of the requested public page. [To confirm: launched features and storage scope] |
| Enquiries and reports — the individual and the system | Enquiry, reply, report content and evidence, linked account, email provided by the reporter, hashed IP and identifiers of the reporting route | Replies, rights requests, handling of reports, appeals, and disputes |
| Consent and operational records — choices and operational actions | Items chosen, time, account, hashed IP and browser information, records of operational measures | Processing of choices, evidence of history, security auditing. Document version: [To confirm: verify what is actually stored] |
The password used for email sign-up is processed for authentication purposes through Supabase Auth. The absence of a password column in the QQRR business database does not mean that the service does not process passwords. The Company does not receive Google passwords.
URLs, free-text entries, public introductions, and responses may contain personal data. The absence of a telephone number field in account settings does not mean that the service as a whole never receives telephone numbers or sensitive information.
Application access logs store a hashed value instead of the raw IP address. This is not guaranteed to be fully anonymous information. Network connections necessarily involve processing of raw IP addresses, and providers' raw logs and access records are addressed separately in Section 6.
3. Grounds for Processing and the Distinction of Consent
| Category | How it applies |
|---|---|
| Account creation and authentication, management of requested links and forms | The scope necessary for a request made in the course of concluding a contract, or for performing the contract. Advertising and all visitor analytics are not included in this ground |
| Statutory retention and orders | Limited to the subject matter, purpose, and period required by the relevant law |
| Use of contact details for advertising purposes, and receipt of advertising | Optional consent for each notified purpose and channel |
| Minimum usage records after withdrawal | Separate optional consent to answer requests to confirm the Member's own link creation, destination selections or form question configuration. Distinct from mandatory Terms and marketing consent; refusal does not prevent sign-up or service use. Items, periods and withdrawal methods are explained in the additional retention document provided alongside this Policy |
| The substance of form responses | The ground obtained by the form owner and the scope of the processing mandate. The owner's consent at sign-up is not the respondent's consent |
| Visitor statistics, security, abuse prevention, disputes, and preservation of evidence | [To confirm: assessment of the minimum items, necessity, and rights impact for each processing activity, and the ground under Article 15 of the Personal Information Protection Act]. "Service improvement" alone is not used to justify all logging |
| Cross-border transfers, sensitive data, and provision to third parties | The statutory requirements for that processing — separate notice, consent, or contract — apply |
In Korea, performance of a contract under Article 15(1)(4) of the Personal Information Protection Act is distinguished from consent under Article 15(1)(1). In Japan, the specification and prior indication of the purpose of use is distinguished from processing that requires separate consent. A ground for processing in one country is not applied as-is to every other country.
If a purpose changes, the Company reviews the relationship to the original purpose and the applicable law, gives notice, and obtains consent before the change where required. Consent for a new purpose is not obtained merely by revising this Policy.
4. Retention Periods and Destruction
Information is retained for as long as necessary for its purpose and destroyed without delay once it is no longer needed. Information subject to separate statutory retention is stored with the items and grounds distinguished. Hiding from display, irrecoverability, and actual deletion are different things.
| Information group | Retention and destruction standard |
|---|---|
| Incomplete sign-up authentication accounts and temporary information | [TBD: determination of incompleteness, period, and Auth deletion procedure] |
| Member accounts and recoverable content | Subject to a recovery request for 90 days after withdrawal. Accounts without a preservation reason become eligible for destruction after the recovery period, with no additional waiting period. Investigation holds and preservation following a confirmed action follow separate criteria. [To confirm: implement the confirmed criteria in code, independently verify them, and approve actual execution] |
| Minimum usage records covered by optional consent | The notified items among the internal account ID, sign-up and withdrawal dates; link creation time, short link and destination; and form identifier, questions, choices and order are stored separately from receipt of the withdrawal request for the periods shown in the consent document. The recovery period is included; periods are not recalculated on destruction of the originals. If records become unnecessary or consent is withdrawn before the period ends, necessary measures, including destruction, are taken without delay, except where the law provides otherwise. This consent alone does not authorize retention of respondent information, attachments, authentication information, reusable payment methods, third-party personal data, sensitive data or secrets. Setting changes do not retroactively extend past consent or deadlines |
| Guest creation and permission information | Link lifetime is one year from creation. The period for destroying the URL, token, and records after expiry is [TBD]. Expiry and destruction are different |
| Click and scan records | Under policy, statistics are retained for Free 3 months / Starter 6 months / Pro 24 months / Business 60 months. [To confirm: the distinction between raw and aggregated data, the start date, truncation calculation, actual destruction, and handling on plan changes] |
| Form responses | The purpose and period stated by the owner on the form. [To confirm: end of the processing mandate, deletion by the owner, account termination, backup arrangements, and actual behaviour] |
| Public introductions and content | Provision ceases on deletion or discontinuation of the feature. Residual periods, image copies, and backups are [To confirm: actual storage and destruction] |
| Records of enquiries, reports, cancellations, and measures | Five years under internal policy. Not every item is a statutory obligation. [To confirm: start date, minimum scope, and ground for each record]. This is not approval to publish a blanket five-year retention |
| Email addresses used for advertising | Until consent to the use of personal data for advertising purposes or consent to receive advertising is withdrawn, or the member withdraws, whichever occurs first. Evidence records are kept separately from the sending list. [To confirm: actual exclusion from sending and destruction] |
| Evidence of advertising consent and withdrawal | Five years after the last advertising message under internal policy. [To confirm: start date for those never sent to, actual destruction, and evidence requirements by jurisdiction] |
| General consent records | Five years under internal policy. [To confirm: ground, start date, minimum evidence, and actual destruction for each type of consent]. Marketing consent and optional additional retention consent evidence are excluded from this standard. Additional retention consent evidence is kept only while needed to process the current signup's choice or substantiate actual additional records, and is cleared when consent is withdrawn or the last additional record for a closed signup is deleted |
| Administrator audit logs | Three years under internal policy. [To confirm: which items contain personal data, the ground for retention, the start date, and actual destruction] |
| Notification records | One year under internal policy, regardless of read status. [To confirm: ground for retention, start date, and actual destruction by notification type] |
| Statutory records of launched transactions | Displays and advertising 6 months; contracts, withdrawal of subscription, payment and supply 5 years; consumer complaints and disputes 3 years. Stored separately according to the record concerned and the applicable law |
The Company identifies the information to be destroyed and deletes electronic information so that it cannot be recovered or reconstructed. Any paper records are destroyed by shredding or a similar method. Deletion in the authentication system, at processors, and in backups is also subject to verification. [To confirm: actual destruction cycle, separation and access restriction, backup expiry, and re-application of deletion after a restore].
Where there is a statutory preservation order or a lawful ground for preserving evidence, deletion may be suspended to the extent necessary. An account is not retained indefinitely merely because of a vague possibility of future dispute or the fact that a report has been received.
5. Provision to Third Parties and Public Disclosure
Personal data is provided to third parties only where permitted by law or where there is another lawful ground such as separate consent. Where a necessary provision arises, the Company will notify at that time the recipient, purpose, items, period, and the consequences of refusal. Processors are distinguished from third parties who use data for their own independent purposes.
Contact details, introductions, and images published through Link in bio, and form screens, may be viewed and copied by visitors. Form responses differ from the public question screen; who may view them and how they may be exported follow the owner's settings and contractual scope.
[To confirm: the current list of third-party provisions, independent processing by payment providers, and transfers to analytics or advertising tools]. Until this is confirmed, the Company will not state definitively that there is "no provision to third parties" or "no sale or sharing".
6. Processing Mandates and Cross-Border Transfers
Where processing is entrusted, the Company reflects in the contract restrictions on processing beyond the purpose, access controls, protective measures, sub-processing, and deletion on termination, and manages the processor. The country of a provider's head office and the country to which data is actually transferred may differ. Even where data is stored domestically, access by overseas support staff, sub-processing, and backups are verified separately.
The following table is to be finalized by contract and configuration, provider by provider. Unverified countries are not replaced with "worldwide".
| Provider and function | Contracting entity and contact | Items and purpose | Country, timing, and method | Retention and transfer ground |
|---|---|---|---|---|
| Supabase — authentication and database | [To confirm] | Authentication and service data. Confirm the scope of Auth, DB, and Storage | [To confirm: countries of storage, support, and backup, and the request and synchronization methods] | [To confirm: contract, deletion, and the route applicable in Korea and Japan] |
| Vercel — web hosting | [To confirm] | The actual items in web requests and logs | [To confirm: countries and timing for functions, logs, and support] | [To confirm: retention and ground] |
| Railway — API hosting | [To confirm] | The actual items in API requests and server logs | [To confirm: countries and timing for the service, logs, and support] | [To confirm: retention and ground] |
| Cloudflare — network | [To confirm] | The actual items processed by the DNS, proxy, and security features in use | [To confirm: whether the proxy is enabled, and the countries of processing and support] | [To confirm: retention and ground] |
| Resend — email | [To confirm: actual use, sending, and contract] | Sender and recipient email addresses, subject, body, and sending logs | [To confirm: countries and timing for transmission, logs, and support] | [To confirm: retention and ground] |
Each row must be finalized down to the exact name of the contracting entity and its personal data contact, the items transferred, the country, the timing and method, the purpose, the retention period, and the method and effect of refusal. Processing mandates and storage necessary for performance of the contract, provisions requiring separate consent, and other permitted routes are distinguished. Required information is disclosed or notified before transfer, and separate consent is obtained where required.
Where Japan's consent-based provision to a foreign third party applies, the Company also explains the data protection regime of the destination country and the recipient's protective measures. Where reliance is placed on an equivalent-measures framework, the Company carries out continuing verification and provides information on request. Not having investigated a country yet does not mean that the exception for an unidentifiable country has been satisfied.
For Google sign-in and payment providers, the Company will verify and disclose whether the relationship is one of independent processing or a processing mandate. Toss Payments and Lemon Squeezy, which are not yet in use, are not presented as processors already receiving personal data.
7. Cookies, Browser Storage, and Tracking
Cookies or browser storage may be used for authentication state, selected settings, guest creation results, and editing previews. These can be deleted or blocked in the browser, but doing so may affect staying signed in or managing guest results.
| Storage or tracking | Purpose | Period and refusal |
|---|---|---|
| Authentication cookies and sessions | Maintaining sign-in and authentication | [To confirm: name, party, scope, and expiry]. Sign out, or delete or block in the browser |
| Guest link storage | Displaying creation results, permission tokens, and expiry information | [To confirm: conditions for removal]. Clear site data. Hiding and deletion are different |
| Preview and settings storage | Retaining editing previews and selections | [To confirm: storage, expiry, and removal behaviour for each item] |
| Cross-site tracking and analytics by third parties | [To confirm: audit of SDKs and network calls] | [To confirm: use, refusal, and handling of signals] |
Do Not Track handling: [To confirm: actual browser and server behaviour]. Application and handling of statutory opt-out signals such as Global Privacy Control: [To confirm: jurisdictional assessment and implementation]. The two signals are not presented as equivalent. If non-essential storage or tracking requiring consent is introduced, a separate means of choice will be provided before it operates.
8. The Roles of Form Owners and the Company
The form owner determines the purpose, items, period, and lawful ground for collecting responses. The Company supports storage, retrieval, export, and deletion within the scope of the processing mandate, as set out in the addendum. The Company does not take the position that it "bears no responsibility because it is a platform" or that "all response data belongs to the Company".
Requests to access or delete the substance of responses may be made to the form owner's contact point. Where the owner cannot be reached, or where the request concerns the Company's own processing, the contact point in Section 11 may be used. The Company performs its own statutory obligations and cooperates with the owner on requests falling within the processing mandate.
9. Rights of Users and Legal Representatives
Users may request access and a copy, correction, deletion, suspension of processing, and withdrawal of consent, in accordance with applicable law. A legal representative or other duly authorized agent may also exercise these rights. The Company processes requests after minimum verification of identity or authority, and explains any grounds for limitation or refusal together with the appeal and remedy procedures.
Where a request cannot be fully performed because of statutory retention or the protection of others' rights, the Company explains the scope and the ground. Cessation of processing after withdrawal is distinguished from the retention of the minimum evidence required by law. Users will not be unfairly discriminated against for exercising their rights. Where a fee permitted by law is actually charged, the ground and amount are explained in advance.
| Region | Additional information |
|---|---|
| Korea | Rights of access, correction, deletion, suspension of processing, and withdrawal under the Personal Information Protection Act, and other rights where the requirements are met. Remedies are available through the Personal Information Protection Commission, the Personal Information Dispute Mediation Committee, and the Privacy Infringement Report Centre |
| Japan | Disclosure of retained personal data and of records of provision to third parties, and correction, suspension of use, deletion, and suspension of provision under the APPI, subject to the applicable requirements and exceptions. Requests for information on equivalent measures for cross-border transfers may also be submitted to the Company's contact point |
| United States | Access, deletion, correction, a portable copy, opt-out of certain processing, and appeal rights vary according to the requirements applicable in each state. [To confirm: the states applicable to QQRR, the rights, deadlines, and request channels] |
| California | Whether the CCPA applies is [To confirm: business status, revenue, purchase/sale/sharing, and contractual relationships]. If it applies, the actual processing categories and the corresponding means of opting out of sale or sharing and of limiting the use of sensitive information will be added. An unconfirmed status is not to be read as "no rights" |
10. Children, Safeguards, and Incident Response
Membership is not offered to persons under the age of 14. This statement alone does not guarantee that no children's data is ever processed. If the Company becomes aware that children's data is contained in an account, form, or enquiry, it will consider the measures required by applicable law, including ceasing processing, deletion, and contacting a guardian. Separate requirements, such as those for children under 13 in the United States, are also taken into account.
The Company implements the necessary measures for access control, protection of authentication credentials, protection in transit, processing records, and management of providers. [To confirm: state only the measures actually in operation, and do not present a provider's certification as the Company's own certification]. If an incident occurs, the Company will notify users, report to the authorities, and mitigate harm in accordance with the requirements and deadlines of applicable law.
11. Officer in Charge, Contact, and Changes
| Item | Details |
|---|---|
| Operator / Representative | DShine / Lee Jinhyeok |
| Personal data protection officer | Lee Jinhyeok |
| Address | 302-S411, 7 Yonggu-daero 2790beon-gil, Suji-gu, Yongin-si, Gyeonggi-do 16866, Republic of Korea |
| service@qqrr.me — [To confirm: whether it is actually monitored and capable of identity verification and processing] | |
| Telephone | [To confirm: contact number to be published] |
| Online requests | [To confirm: an actual request URL usable by non-members] |
Material changes to processing are published so that the content and effective date can be readily identified, together with any individual notice or consent that is required. A history is provided showing previous policies and their respective effective dates.
Effective date: [TBD]. Document version: [TBD]. Previous policy: [To confirm: URL of the publication history].