The Korean version of this policy is the original. In case of any discrepancy with a translation, the Korean original prevails.
View Korean originalStandbyWorks (the "Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of Korea, in order to protect the personal data of data subjects and to handle related grievances promptly and smoothly.
The Company processes the minimum personal data necessary for the purposes below. Personal data is not used for any purpose other than those stated, and where the purpose changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of PIPA.
| Category | Purpose | Items collected | Legal basis |
|---|---|---|---|
| Individual / SNS member | Identity verification, confirmation of sign-up, service use and consultation | Name, email, mobile number, ID, password, profile information (for SNS sign-up) | Performance of contract (required) |
| Business member | Provision of business services, issuance of tax invoices | Company name, business registration number, representative name, contact person details (name, phone, email) | Performance of contract (required) |
| Orders and payments | Purchase and payment, delivery of goods, identity verification for financial transactions | Payment method details, payment amount, approval number, recipient details (name, phone, address) | Contract / legal duty (required) |
| Marketing / advertising | Notice of new services, delivery of promotional information, event announcements | Email address, mobile number | Consent (optional) |
| Automatically collected | Service usage statistics, prevention of fraudulent use, retention of access logs | IP address, cookies, service usage records (visits, searches, purchases), access logs, device and browser information | Generated automatically during service use |
| Use as a production example | Showcasing production examples and promotion through official channels under Article 33 of the Terms | Images of completed production works excluding personal data and order identifiers; privacy and removal request records | Service contract and Article 33 of the Terms |
Consent to receive advertising messages remains optional and is separate from the production-work licence. The Company excludes works revealing personal data and removes them from channels under its control upon request. The Company does not collect sensitive data or unique identifiers.
The Company processes and retains personal data within the period required by law or consented to by the data subject, and destroys it without delay once the purpose has been achieved. Records that must be preserved under the laws below are stored separately from other personal data in a dedicated database and are not used for any purpose other than preservation.
To ensure continuity of the custom production service and for your convenience, the Company manages order data as follows.
All production-related data — original design files, quick reorder records, and thumbnails used to review order history — is securely retained for one year from the order date and then permanently deleted.
This allows design data to be reused conveniently on reorder and production history to be verified. Source design files are not used for promotion, advertising, or AI regeneration. Under Article 33 of the Terms, only an image of the completed production work with personal data removed may be used as a production example. Data subjects may request deletion of production data or removal of a production example at any time using the methods in Article 12.
Should the Company permanently terminate the service (e.g. closure of business), the following measures will be taken.
The reason and date of termination will be announced at least 30 days before the scheduled termination date, through website notices and other channels.
Upon termination, your account information and all personal data held on the site will be securely destroyed in a manner that prevents recovery.
Unused credits and points may expire automatically on the termination date, so we recommend using them in advance.
When personal data becomes unnecessary — because the retention period has elapsed or the purpose has been achieved — the Company destroys it without delay.
Data subject to destruction is identified and destroyed with the approval of the Chief Privacy Officer.
Electronic files are permanently deleted in a manner that prevents recovery or reproduction; paper documents are shredded or incinerated.
Data that must be preserved by law is moved to a separate database or stored in a different location, and is not used for any purpose other than preservation.
The Company processes personal data only within the scope specified in Article 1 and does not provide it to third parties except in the following cases under Articles 17 and 18 of PIPA.
The Company entrusts personal data processing tasks as follows in order to provide the service smoothly.
| Entrusted task | Processor | Country of processing |
|---|---|---|
| Payment gateway integration | Korea PortOne (PortOne) | Republic of Korea |
| Payment and settlement | KG Inicis | Republic of Korea |
| Overseas payment | PayPal, Inc. | United States |
| Delivery of ordered products | CJ Logistics, Korea Post and other partner carriers | Republic of Korea |
| Notification service | Aligo (KakaoTalk AlimTalk and SMS delivery) | Republic of Korea |
| Data infrastructure | Supabase Inc. (DB / Storage — Seoul region) | Republic of Korea |
| Service hosting | Vercel Inc. | United States |
| AI image tools | Kaleido AI GmbH (remove.bg), Replicate, Inc., Google LLC | Austria · United States |
| Customer support | KakaoTalk channel "StandbyWorks" | Republic of Korea |
| AI image analysis, generation and editing | OpenAI, L.L.C. | United States |
When entering into an entrustment agreement, the Company specifies in writing — pursuant to Article 26 of PIPA — the prohibition of processing beyond the entrusted purpose, technical and administrative safeguards, restrictions on sub-entrustment, supervision of the processor, and liability including damages, and supervises whether the processor handles personal data safely. Any change to the entrusted tasks or processors will be disclosed through this policy.
Pursuant to Article 28-8 of PIPA, the Company transfers personal data overseas as set out below. In every case the time and method of transfer is transmission over the network at the moment the relevant feature is used. Data subjects may refuse the overseas transfer; if refused, the corresponding features (overseas payment, AI image tools, personalised advertising, etc.) may be unavailable.
| Recipient | Country | Items transferred | Purpose | Retention period |
|---|---|---|---|---|
| Vercel Inc. | United States | Access IP, access logs, service usage records | Website hosting and traffic handling | Until termination of the entrustment agreement |
| PayPal, Inc. | United States | Payer name, email, payment information | Processing of overseas payments | Retention period required by applicable law |
| Kaleido AI GmbH (remove.bg) | Austria | Images uploaded by the user | Image background removal | Destroyed without delay after processing |
| Replicate, Inc. | United States | Images uploaded by the user | Image upscaling | Destroyed without delay after processing |
| Google LLC | United States | Entered text prompts, separately consented images and design files, generation or editing instructions, cookies, advertising identifiers, and web/app usage history | AI copy assistance, generation or editing of separately consented advertising images, usage analytics, and personalised advertising | The Company deletes its processing copy without delay after completion. Google may retain paid-service safety and abuse-monitoring logs for up to 55 days. Cookies and usage history are retained for up to 1 year or until consent is withdrawn |
| Meta Platforms, Inc. (Facebook · Instagram) | United States | Cookies, web/app usage history | Personalised advertising | Up to 1 year, or until consent is withdrawn |
| OpenAI, L.L.C. | United States | Separately consented image/design files, prompts, and generation/editing instructions | Reference-image analysis and generation/editing of separately consented advertising images | The Company deletes processing copies without delay after completion; the provider may retain limited data for API safety and abuse monitoring |
To refuse an overseas transfer, use the cookie-blocking methods in Article 10 or contact the Chief Privacy Officer listed in Article 14.
The Company takes the following administrative, technical and physical measures to keep personal data secure.
An internal management plan is established and implemented, the number of staff handling personal data is minimised, and security training is conducted regularly.
Passwords are stored using one-way encryption that cannot be reversed, and data in transit is encrypted with SSL/TLS.
Access rights to the personal data processing system are granted at the minimum level required for the job, and records of granting, changing and revoking rights are maintained.
Access logs of the personal data processing system are retained and reviewed so that they cannot be forged, altered, stolen or lost.
Security measures against hacking and malware are applied, and system security updates are applied periodically.
Servers holding personal data are located in cloud providers' data centres, and physical access control to those facilities is carried out by the processor.
The Company uses cookies to provide personalised services. Cookies are used to understand visit frequency, visit duration and usage patterns.
Essential cookies
Cookies strictly necessary to provide the service, such as keeping you logged in, security (CSRF protection) and cart persistence. Refusing them will restrict use of the service.
Optional cookies
Cookies for usage analytics and personalised advertising. Refusing them does not restrict use of the service.
How to refuse cookies and advertising identifiers
If you refuse to store all cookies, you may experience restrictions when using services that require sign-in.
The Company processes behavioural data as follows in order to provide optimised benefits and advertising.
| Collected / processed by | Items collected | Purpose | Retention period |
|---|---|---|---|
| Google (Analytics · Ads) | Web/app visit and usage history, cookies, advertising identifiers | Usage analytics and personalised advertising | Up to 1 year |
| Meta (Facebook · Instagram) | Web/app visit and usage history, cookies | Personalised advertising | Up to 1 year |
Data subjects may exercise the following rights against the Company at any time, and the Company will act on them without delay.
How to exercise your rights
Right to data portability
Data subjects may request that their personal data be transmitted to themselves or to another controller. Transferable items are membership information and order history, provided in CSV or JSON format. Requests are received through the contact details above, and the status and record of the transfer are sent back to the contact you used.
Children under 14
Personal data of children under 14 is processed with the consent of a legal representative, who may request access, correction, deletion or suspension of processing of the child's personal data.
Exercise through a representative
Rights may also be exercised through a legal representative or an authorised agent, in which case a power of attorney in the form of Annex 11 of the Public Notice on the Methods of Processing Personal Data must be submitted.
Department receiving and handling access requests
Customer Support (Kim Donghyun) · +82-70-8997-8420 · info@standbyworks.com
The Company does not make decisions that significantly affect the rights or obligations of data subjects solely by means of a fully automated system, as referred to in Article 37-2 of PIPA.
Membership tier calculation and reward rates are computed automatically based on the cumulative purchase thresholds published in the Terms of Service, and the AI image tools provided by the Company merely process images uploaded by the user — they do not evaluate or make decisions about data subjects. If you disagree with a result, you may ask customer support to review and correct it.
The Company has designated a Chief Privacy Officer who is overall responsible for personal data processing and for handling complaints and providing remedies for data subjects.
Name
Kim Donghyun
Position
Chief Privacy Officer
Contact
+82-70-8997-8420
info@standbyworks.com
Grievance handling
Customer Support · +82-70-8997-8420 · info@standbyworks.com (weekdays 10:00–17:00 KST; closed weekends and public holidays)
Data subjects may apply to the following bodies for dispute resolution or consultation regarding infringement of their personal data rights. You may also contact these bodies if you are not satisfied with the outcome of the Company's own complaint handling.
This Privacy Policy applies from its effective date. Where content is added, deleted or corrected under applicable law or this policy, the change will be announced through website notices at least 7 days before it takes effect (30 days in advance where the change is unfavourable to data subjects).
Revision history
Effective Date: 27 Sep 2026 (first effective 18 Jan 2026)
© 2026 STANDBY WORKS. ALL RIGHTS RESERVED.