Service and data processing notice
1. Controller and purposes. The operator identified below processes personal data for account management, requested analysis and storage, subscriptions, security, support and legal obligations. Necessary contract processing relies on Article 15(1)(4) of Korea's Personal Information Protection Act; processing required by law relies on Article 15(1)(2). Optional processing requiring consent has a separate notice describing the data, purpose, period and right to refuse.
2. Account and access information. Registration collects email, display name and password; passwords are stored as hashes. We process account creation, update and verification times, session tokens, IP addresses, browser information and security records. If you use multifactor authentication, we process encrypted authentication secrets, hashed recovery codes and authentication records. We send verification and password-reset emails.
3. Analysis and optional features. Saved commanders, tactics, books, equipment, progression, formations, game, season, language, region, requests, results and usage are linked to your account. Sharing, alliance, referral and affiliate features process public result summaries, membership and roles, invitations, referral and reward records, and affiliate display names, channel URLs and applications. You need not submit feature-specific data when you do not use that feature.
4. Billing and support. We process billing country, product, amount, currency, tax, provider customer, transaction and subscription identifiers, payment, refund and renewal status, and checkout acknowledgment records. Paddle's checkout handles card numbers and security codes; our server does not store them. Support uses account ID, email, category, message and handling records. Queued email content is encrypted. Do not include unnecessary national identifiers, card details or other sensitive material in support messages.
5. Usage records. Our own systems record user IDs or hashed identifiers, times, language, region, game context and necessary feature events for delivery, usage administration and error handling. We do not use these records for automated decisions with legal or similarly significant effects on individuals. Battle recommendations concern the game formations you supply.
6. Retention. Account, inventory and saved results are retained while you use the service and removed when account closure or a relevant deletion request is processed. Where Korean e-commerce law requires retention, contract, withdrawal, payment and delivery records are kept for five years, consumer complaints and disputes for three years, and advertising records for six months. Only necessary identifying, transaction or support fields are retained for those purposes. Specific operational log, email-job and backup periods and exceptions appear in the retention notice below.
7. Erasure. We erase unnecessary data without undue delay when its purpose or retention period ends. Legally retained records are separated from ordinary service data with restricted access and recorded grounds, fields and periods. Electronic records are deleted to prevent recovery; paper records are shredded or destroyed. Previously processed deletion requests must also be applied when restoring backups. Staff process account-closure and rights requests after identity verification.
8. External processing and international transfers. Data entered into Paddle's checkout and the product, country and internal transaction identifiers we send are used by Paddle to sell and process payment; we receive payment status. Paddle handles buyer data under its own privacy policy. The processor and transfer notice below identifies hosting, database and email providers and relevant overseas recipients, countries, fields, purposes, timing, methods, retention, legal grounds and refusal options. Separate transfer consent is obtained before a transfer where required.
9. Disclosure and sharing. A share link makes its public analysis summary available to anyone holding the link; recipients' saved copies may survive revocation. Alliance features display membership and role information needed for the feature. Other third-party disclosure occurs only with consent or another lawful basis and within its necessary scope. Share links do not expose full inventories or authentication credentials.
10. Cookies and device storage. We use essential authentication and request-forgery protection cookies, localStorage for inventory, analysis cache, settings and alliance credentials, and sessionStorage for referral codes. The default sign-in session lasts seven days and may renew with use. Browser settings let you block cookies or clear site data, which may affect sign-in and saved settings. On shared devices, sign out and clear stored site data.
11. Your rights and safeguards. You or an authorized representative may request access, correction, erasure, restriction, consent withdrawal and legally available portability through the privacy contact or support below. Email or telephone requests remain available if you cannot sign in. We verify identity or authority, review retention obligations, and respond within applicable deadlines or explain restrictions. Consent-based processing of children under 14 requires verified legal-representative consent; unlawfully collected child data is addressed through restriction or deletion. Safeguards include restricted access, credential hashing, encryption and security records.
12. Contact and changes. The privacy officer or responsible department's contact is listed below. You may also seek help from Korea's privacy infringement reporting centre at 118 or the Personal Information Dispute Mediation Committee. We publish the effective date and material changes to this policy and obtain new consent before processing that requires it.
Operator information
- Operator
- 전략판랩
- Representative
- 이석원
- Address
- 부산광역시 기장군 정관읍 정관5로 12, 206동 103호
- Business registration number
- 661-50-01100
- Mail-order business registration
- 통신판매업 신고 면제
- Support telephone
- 010-4139-0080
- Support email
- iseogwon45@gmail.com
- Privacy contact
- 이석원 · iseogwon45@gmail.com · 010-4139-0080
- Processors and international transfers
- 전략판랩의 처리 업체·국외 이전 안내입니다. 각 업체의 보유기간은 이어지는 보존기간 고지에 따릅니다. 1. Cloudflare, Inc. — 웹 전달·보안, 웹 서버와 분석 작업 실행을 위탁합니다. 서비스 접속·기능 사용 시 IP·접속 시각·URL·브라우저 정보, 쿠키·세션, 가입·로그인 정보, 저장·분석·문의 입력과 응답이 HTTPS로 전달·처리됩니다. 비밀번호는 가입·로그인 요청 처리 후 DB에 해시로 보관합니다. 같은 업체의 Email Sending으로 인증·비밀번호 재설정·문의 전달 메일을 발송합니다. 발신·수신 주소, 제목·본문(인증·재설정 링크와 문의 내용 포함), 헤더, 전송 시각과 전달·반송 정보가 발송 시 서버와 Cloudflare 사이의 암호화된 SMTP 연결로 전송됩니다. 악성코드·피싱·스팸 탐지를 위한 자동 내용 검사가 이루어질 수 있습니다. 웹·메일은 국가 제한 없는 글로벌 구성이며 한국 전용 처리가 아닙니다. Cloudflare는 주된 저장지역을 미국·유럽경제지역(EEA)으로 안내하고 전 세계 이전·접근을 허용합니다. 네트워크와 재수탁자별 지역: https://www.cloudflare.com/network/ ; https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/ . 연락처: privacyquestions@cloudflare.com. 2. Supabase Pte. Ltd. — 계정·세션·인증, 저장한 보유 목록·편성·설정·분석 결과·이용 기록, 약관 확인과 암호화된 메일 발송 작업을 보관하는 PostgreSQL 운영을 위탁합니다. 주 DB는 대한민국 서울(ap-northeast-2)이며 기능 실행 시 서버가 암호화된 DB 연결로 읽고 씁니다. Data API는 비활성입니다. 계약상 지정 지역에 저장·주로 처리하되 서비스 제공·법령 준수·추가 지시에 필요한 경우 Supabase와 재수탁자의 다른 시설에서 처리할 수 있고 국외 인력이 지원·운영에 관여할 수 있습니다. 계약·재수탁 업무: https://supabase.com/legal/customer-resources/data-processing-addendum ; https://supabase.com/legal/customer-resources/subprocessor-list . 연락처: privacy@supabase.io. 3. Google LLC — 문의 수신·답변에 개인 Gmail(iseogwon45@gmail.com)을 이용합니다. 문의·회신 시 이메일, 계정 식별자(웹 문의), 제목·본문·답변·헤더가 메일로 전달·처리됩니다. 미국·대만·일본·싱가포르 등을 포함한 Google의 전 세계 서버에서 처리될 수 있으며 한국 저장으로 제한되지 않습니다. 공개 시설: https://datacenters.google/locations/ . 개인정보정책: https://policies.google.com/privacy?hl=ko . Google 연락처: https://support.google.com/policies/troubleshooter/2990837 . 계약 체결·이행에 필요한 국외 처리위탁·보관은 개인정보 보호법 제28조의8 제1항 제3호에 따른 공개·고지 방식으로 처리하며 별도 동의가 필요한 이전은 사전에 동의를 받습니다. 이전 거부·삭제·처리정지 요청은 개인정보 담당자 이석원(iseogwon45@gmail.com, 010-4139-0080)에게 접수할 수 있습니다. 이메일 처리를 원하지 않으면 전화로 문의할 수 있습니다. 필수 서버·인증 처리를 거부하면 해당 계정·저장·분석 기능 이용이 제한될 수 있습니다. 유료 결제는 비활성 상태이며 Paddle 처리사항은 결제 개통 전에 안내합니다.
- Retention
- 1. 계정·보유 목록·저장 결과는 서비스 이용 중 보관하고, 탈퇴 또는 해당 자료의 삭제 요청을 담당자가 본인 확인과 법적 보존 여부 검토 후 처리할 때 파기합니다. 일반 문의의 접수·본문·답변과 발송 자료는 문의 처리에 필요한 동안 보관하며, 처리 종결 후 추가 보유 필요와 법적 의무를 확인하여 담당자가 직접 파기합니다. 문의 메일에는 아래 인증 자료 정기 삭제 기준을 적용하지 않습니다. 권리 요청 연락처: 이석원, iseogwon45@gmail.com, 010-4139-0080. 2. 로그인 세션의 기본 유효기간은 7일이며 이용에 따라 갱신됩니다. 이메일 인증 링크는 24시간, 비밀번호 재설정 링크는 30분 유효합니다. 만료된 세션·인증 토큰은 만료 후 7일을 기준으로 정기 정리합니다. 가입 인증·비밀번호 재설정용으로 구분된 메일 작업은 발송 성공 완료 후 7일, 최종 실패·취소 완료 후 30일을 기준으로 암호화된 본문과 연결된 발송 시도 기록을 정리합니다. 진행·재시도 중인 자료와 다른 처리에서 사용 중인 자료는 해당 자동 정리에서 제외합니다. 법적 보존 검토나 장애·처리 적체로 정리가 보류되면 담당자가 확인하여 처리합니다. 토큰 사용 만료와 DB 기록 삭제는 별개입니다. 3. Cloudflare Workers Paid 운영 로그는 최대 7일, 공급자 처리 인프라의 접근 감사기록은 12개월 보관됩니다. Email Sending의 주소·제목·메시지 식별자·오류를 포함한 발송 이벤트·분석 자료는 31일 보관됩니다. 이메일 미리보기가 켜진 동안 발송된 메시지의 본문·헤더·원문 미리보기는 약 7일 보관됩니다. 반송 차단은 일시적 반송 기본 24시간, 일부 영구적 반송 7일 동안 유효하며, 존재하지 않는 주소·도메인, 반복 실패·스팸 신고 항목은 자동 만료되지 않을 수 있습니다. 차단 항목 만료는 모든 사본의 삭제 완료를 뜻하지 않습니다. 공급자 관리 항목은 지원 절차를 거쳐 삭제·정정을 요청합니다. Cloudflare는 법률상 보존 의무를 제외하고 계약 종료·만료 또는 서비스 완료 후 고객 선택에 따라 개인정보와 사본을 삭제하거나 반환합니다. 근거: https://developers.cloudflare.com/email-service/observability/logs/ ; https://developers.cloudflare.com/email-service/observability/metrics-analytics/ ; https://developers.cloudflare.com/email-service/concepts/suppressions/ ; https://www.cloudflare.com/cloudflare-customer-dpa/ . 4. Supabase와의 계약 종료 후에는 30일의 반환 요청기간이 끝나면 계약 대상 데이터의 사본을 삭제하도록 정합니다. 이는 회원 탈퇴 후 일률적인 추가 보관기간이 아닙니다. DB에서 삭제한 자료의 공급자 운영 백업·로그에는 별도 삭제 절차가 적용됩니다. 서울 Free DB 이용이 백업의 부재나 즉시 완전 삭제를 의미하지 않습니다. 계약 근거는 위 Supabase DPA 제11.2조입니다. 5. 문의 목적이 끝나고 보존 의무가 없는 Gmail 메일은 담당자가 휴지통에서도 영구 삭제합니다. Google의 일반 삭제 절차는 통상 약 2개월이며 암호화된 백업에는 최대 6개월 남을 수 있습니다. 안전한 삭제에 필요한 추가 시간, 장애와 법적·보안상 보존 사유에 따른 예외가 있습니다. 공급자 기준: https://policies.google.com/technologies/retention . 6. 법령상 보존 대상인 계약·청약철회 및 결제·공급 기록은 5년, 소비자 불만·분쟁 처리 기록은 3년, 표시·광고 기록은 6개월 보존합니다. 필요한 항목만 일반 이용 자료와 분리하여 법정 목적에 사용합니다. 개인정보처리시스템의 개인정보취급자 접속기록은 법령상 해당하는 경우 1년 이상, 강화 기준 대상이면 2년 이상 보존합니다. 법적 보존이 필요한 자료는 근거·범위·기간을 관리하고, 보유기간 종료 또는 목적 달성으로 불필요해진 자료는 지체 없이 파기합니다. 백업 복원 시 기존 삭제 요청을 함께 반영합니다.
- Effective date
- 2026-09-21