Table of Contents
Revision Notice
We revised this Privacy Policy to reflect, in the transferred items, the hashed email address and hashed member identifier that our server has begun transmitting to Meta at sign-up. Only SHA-256 hashed values are transmitted, never the raw values.
Effective Date 2026-08-25
Key Changes
- “6. Overseas Transfer of Personal Information” — added the hashed email address and hashed member identifier to the items transferred to Meta Platforms, Inc.
Contact — Please contact dev@intellieffect.com.
LEGAL
Privacy Policy
IntelliEffect (the "Company") complies with the Personal Information Protection Act (PIPA, Korea) and other applicable laws, and establishes and discloses the following Privacy Policy in order to safely process users' personal information. This Policy applies to the Castera service operated by the Company.
At a Glance
Information We Collect
Account information such as email address and display name, service usage records, and cookies and advertising identifiers used for analytics and advertising performance measurement.
Purpose of Use
Used to provide the Service, including member authentication, Creator–Brand matching, contract execution, payment, and settlement.
Retention Period
Destroyed without delay upon withdrawal of membership. Only information subject to a statutory retention obligation is retained as an exception.
Contact
For privacy-related inquiries, please contact dev@intellieffect.com.
1. Personal Information Collected and Methods of Collection
The Company collects the following personal information during member registration, provision of the Service, and the payment/settlement process.
| Category | Applicable To | Items Collected | Time of Collection |
|---|---|---|---|
| Required | All Members | Email address, password (for email registration · stored using one-way encryption), display name, role information (Creator/Brand) | At registration and onboarding |
| Required | All members | Age confirmation consent — the member confirms they are 19 or older; only the consent and its timestamp are recorded (no additional identity data is collected for this) | At sign-up and onboarding |
| Required | When using social login | Social account identifier, email address, profile name (provided by Google · LINE) | When linking a social account |
| Required | Creator Members | SNS handle in operation (account URL), area of activity | At Creator registration |
| Required | Brand Members | Company (brand) name, contact person information, industry | At Brand registration |
| Required | When using payment/settlement | Payment approval information (original payment instrument data not retained), settlement account information, tax invoice issuance information | At payment/settlement |
| Automatically collected | All users | Access logs, device/browser information, service usage records, error logs, cookies and advertising identifiers, ad referral and conversion records | During use of the Service |
The original data of payment instruments, such as card numbers, is processed by the electronic payment service provider (Toss Payments), and the Company does not store it.
2. Purposes of Processing Personal Information
Personal information collected is processed for the following purposes, and where the purpose changes, separate consent will be obtained in accordance with applicable laws.
- Member registration, authentication, and management — identity verification, prevention of fraudulent use, and various notices
- Age verification — blocking registration by anyone under 19 (confirmed by the member's own consent)
- Provision of the Service — Creator–Brand matching, support for executing and performing Campaign contracts, inter-Member messaging functions
- Payment processing, escrow deposit, and settlement processing
- Maintaining a safe transaction environment — preventing circumvention transactions, responding to disputes, protecting accounts
- Service improvement and statistical analysis (in a form that does not identify individuals)
- Fulfilling obligations under applicable laws
Where personal information is used for marketing purposes, separate consent will be obtained, and use of the Service is not restricted if consent is not given.
3. Retention and Use Period of Personal Information
In principle, the Company destroys personal information without delay upon a Member's withdrawal. However, in the following cases, the information is stored separately for the relevant period before being destroyed.
| Basis for Retention | Items Retained | Period |
|---|---|---|
| Act on the Consumer Protection in Electronic Commerce, etc. (Korea) | Records relating to contracts or withdrawal of subscription | 5 years |
| Act on the Consumer Protection in Electronic Commerce, etc. (Korea) | Records relating to payment and supply of goods, etc. | 5 years |
| Act on the Consumer Protection in Electronic Commerce, etc. (Korea) | Records relating to consumer complaints or dispute handling | 3 years |
| Protection of Communications Secrets Act (Korea) | Service access records | 3 months |
| Internal policy (fraud prevention) | Records relating to fraudulent registration or restriction of use | 1 year after withdrawal |
A Creator's SNS handle is deleted within 30 days of the Member's withdrawal, in accordance with the SNS Handle Non-Disclosure Policy.
4. Provision of Personal Information to Third Parties
In principle, the Company does not provide users' personal information to outside parties, and provides it only where the user has given prior consent or there is a legal basis for doing so.
Given the nature of the Service, the following provision occurs during the process of executing a Campaign contract.
| Recipient | Items Provided | Purpose of Provision | Retention/Use Period |
|---|---|---|---|
| The counterparty Brand Member with whom a Campaign contract has been executed | Creator's SNS handle | Performance of the executed Campaign contract — disclosed upon execution of the contract and full deposit of the payment into escrow | Until the purpose of the contract is achieved |
Before a contract is executed, a Creator's SNS handle is not provided to any advertiser under any circumstances. Please refer to the SNS Handle Non-Disclosure Policy for details.
5. Outsourcing of Personal Information Processing
To provide a stable Service, the Company outsources personal information processing tasks as follows.
| Processor | Outsourced Task |
|---|---|
| Supabase, Inc. | Database operation and member authentication infrastructure |
| Vercel Inc. | Service hosting and web analytics (cookieless) |
| Google LLC | Website usage analysis (Google Analytics 4) and targeted advertising and conversion measurement (Google Ads) |
| Meta Platforms, Inc. | Targeted advertising and ad performance and conversion measurement (Meta Pixel and server-side transmission via Conversions API) |
| Toss Payments Co., Ltd. | Electronic payment processing (including escrow) |
When entering into an outsourcing agreement, the Company stipulates compliance with applicable personal information protection laws, restrictions on re-outsourcing, and technical and administrative protective measures, and supervises the processor.
6. Overseas Transfer of Personal Information
The servers of some cloud services used by the Company are located overseas, and personal information is transferred overseas as follows in the course of using the Service.
| Recipient | Country | Items Transferred | Method/Time of Transfer | Retention Period |
|---|---|---|---|---|
| Supabase, Inc. | United States, etc. | Account information, service usage data | Transmitted and stored via the information and communications network when using the Service | Until termination of the outsourcing agreement or withdrawal of membership |
| Vercel Inc. | United States, etc. | Access records, de-identified web analytics data | Transmitted via the information and communications network when accessing the Service | Until the purpose of collection is achieved |
| Google LLC | United States | Cookie and advertising identifiers, visit and page view records, referral sources, ad click and conversion records, device and browser information, approximate location (city level) | Transmitted via the information and communications network when accessing the Service | 14 months for usage analysis; ad conversion data until the end of the period under Google's retention policy |
| Meta Platforms, Inc. | United States | Cookie and advertising identifiers, IP address, visit and page view records, ad click and conversion records (sign-up, inquiry, etc.), device and browser information, approximate location, hashed email address, hashed member identifier | Transmitted via the information and communications network when accessing the Service and when a conversion occurs | Until the end of the period under Meta's retention policy |
Users may refuse the overseas transfer of their personal information. However, because overseas transfer is essential infrastructure for providing the Service, use of the Service may be restricted if refused. A refusal request may be made to dev@intellieffect.com.
7. Procedure and Method for Destruction of Personal Information
The Company destroys personal information without delay once it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.
Information in electronic file form is deleted using a technical method that prevents recovery, and paper documents are destroyed by shredding or incineration. Information that must be retained under applicable law is stored separately in a separate storage space and destroyed immediately upon expiry of the retention period.
8. Users' Rights and How to Exercise Them
Users may exercise the following rights against the Company at any time, and the Company shall take action without delay within the period prescribed by applicable law.
Rights may be exercised through the settings screen within the Service or by email (dev@intellieffect.com), and may also be exercised through a legal representative or an authorized agent. In such a case, a power of attorney in accordance with applicable law must be submitted.
- Request to access personal information
- Request for correction where there is an error
- Request for deletion
- Request to suspend processing
- Withdrawal of consent to the collection and use of personal information (withdrawal of membership)
The exercise of rights may be restricted where applicable law mandates the collection or retention of the relevant personal information, and in such a case the reason will be provided.
10. Measures to Ensure the Safety of Personal Information
The Company takes the following measures to ensure the safety of personal information.
- Administrative measures — establishing and implementing an internal management plan, minimizing access privileges to personal information, and managing access records
- Technical measures — one-way encrypted storage of passwords, encryption of data in transit (TLS), database access control, and application of Row Level Security
- Physical measures — utilizing the cloud provider's physical access controls and security certification systems
- Minimizing access privileges to, and managing access logs for, highly sensitive information such as SNS handles
11. Data Protection Officer and Contact
The Company designates a Data Protection Officer as set out below, who oversees personal information processing and handles users' complaints and remedies relating to the processing of personal information.
Users may direct any inquiry, complaint, or request for remedy relating to personal information arising from use of the Service to the contact below, and the Company will respond and address it without delay.
| Category | Details |
|---|---|
| Data Protection Officer | CEO of IntelliEffect |
| Contact Email | dev@intellieffect.com |
12. Remedies for Infringement of Rights
Users who need to report or consult regarding an infringement of personal information may contact the following institutions.
| Institution | Contact | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) | www.kopico.go.kr |
| KISA Privacy Center (Korea Internet & Security Agency) | 118 (no area code) | privacy.kisa.or.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | 1301 (no area code) | www.spo.go.kr |
| National Police Agency Cyber Investigation Bureau | 182 (no area code) | ecrm.police.go.kr |
13. Duty to Notify and Amendments
Where the content of this Privacy Policy is added, deleted, or amended, notice will be given through the Service's announcements starting 7 days before the effective date. However, where an amendment materially affects users' rights, such as a change in the items collected or provision to third parties, notice will be given 30 days before the effective date, and separate consent will be obtained again where necessary.
Data Protection Officer & Contact
Data Protection Officer
CEO of IntelliEffect
Handles inquiries and requests to access, correct, delete, and suspend processing of personal information.
Revision History
- v7 · 2026-08-25 — Reflected the hashed email address and hashed member identifier that are now included in server-side transmission to Meta (Conversions API) — hashed with SHA-256 at sign-up; raw values are never transmitted
- v6 · 2026-08-19 — Reflected the IP address already being transmitted via Meta server-side transmission (Conversions API) in the transferred items — outsourced tasks now note server-side transmission (Conversions API), and IP address was added to the overseas transfer items
- v5 · 2026-08-05 — Removed date of birth as a collected item — the 19+ check is now a member's own confirmation consent (only the consent and its timestamp are recorded)
- v4 · 2026-08-04 — Added date of birth as a collected item for the 19+ age check — stated as not retained after verification
- v3 · 2026-08-03 — Reflects the introduction of advertising tools — discloses the use of Meta Pixel and Google Ads tags, adds cookies/advertising identifiers and conversion records to automatically collected items, adds Meta Platforms to processors and overseas transfers, and provides opt-out methods for targeted advertising
- v2 · 2026-07-28 — Complete revision — reorganized the table of items collected; added outsourcing of processing, overseas transfer, provision to third parties, safety measures, and remedies for infringement of rights
- v1 · 2026-05-18 — Initial enactment
This document is currently under legal review, and some content may be adjusted based on the review outcome.