Daysmate (hereinafter the "Service") processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act and related laws, in order to protect the freedom and rights of data subjects. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Service establishes and discloses the following Privacy Policy to inform data subjects of the procedures and standards for processing their personal information and to handle related grievances promptly and smoothly.
제1조 (Purpose of Processing Personal Information)
The Service processes personal information for the following purposes.
- Member registration and management: identifying members, verifying identity, and preventing fraudulent use of accounts
- Service provision: registering and storing anniversaries and events, and sending reminder emails
- Responding to customer inquiries and handling disputes
제2조 (Categories of Personal Information Processed)
The Service processes the following categories of personal information.
a. At registration (required)
- Email address
- OAuth identifier (the user identification ID provided by the social login provider, such as Google / Apple / Kakao / Naver)
b. At registration (optional)
- Nickname or display name
- Notification email address (if different from the registration email)
c. Information entered directly by the user while using the Service
- The title, date, and notes of registered anniversaries and events
- Display time zone and language settings
d. Information collected automatically during use of the Service
- Access IP address, browser type, and access date and time
- Authentication cookies for keeping you signed in
제3조 (Retention and Use Period)
The Service processes and retains personal information within the retention and use period required by law or the retention and use period consented to by the data subject at the time of collection.
- Member registration and management: until the member withdraws
- After a withdrawal request: up to 30 days (the period during which withdrawal can be cancelled). After 30 days, the data is automatically and permanently deleted.
- Where retention is required by relevant laws, the data is retained for the period prescribed by those laws.
제4조 (Provision to Third Parties)
The Service processes the personal information of data subjects only within the scope of the purposes specified in Article 1, and does not provide it to third parties without the data subject's prior consent. The following cases are exceptions.
- Where the data subject has given prior consent
- Where there is a special provision in the law, or where there is a request from an investigative agency in accordance with lawful procedures
제5조 (Delegation of Processing)
To provide the Service smoothly, the Service delegates personal information processing tasks as follows.
| Processor | Delegated work | Country |
|---|
| Supabase Inc. | User authentication and database operation | United States / Japan (Tokyo region) |
| Resend Inc. | Sending reminder emails | United States |
| Vercel Inc. | Web hosting and deployment | United States |
| Cloudflare, Inc. | DNS and email routing | United States |
All of the above processors handle personal information processing tasks that are essential for providing the Service, and process such data overseas while applying appropriate safeguards such as relevant laws and Standard Contractual Clauses (SCC).
제6조 (Rights of Data Subjects and How to Exercise Them)
Data subjects may exercise the following rights at any time.
- Right to access personal information — available in the Service's settings menu
- Right to correct personal information — can be edited directly in the Service's settings menu
- Right to delete personal information — request withdrawal in the Service's settings menu
- Right to request suspension of processing — request via privacy@daysmate.com
Where a legal representative or an authorized person exercises rights on behalf of the data subject, a power of attorney must be submitted.
제7조 (Security Measures)
The Service takes the following measures to ensure the security of personal information.
- Technical measures: TLS encryption in transit, encryption of data stored in the database, and separation and control of access privileges
- Administrative measures: establishment and implementation of a privacy policy, and regular training for personnel who process personal information
- Physical measures: access control to data centers (on the processor's side)
- No password storage: the Service does not store its own passwords and authenticates users only through OAuth providers (Google / Apple / Kakao / Naver).
제8조 (Destruction Procedure and Method)
When a member requests withdrawal, all personal information is automatically and permanently deleted from the database 30 days after the request date. If the member signs in again within 30 days and chooses to restore the account, the deletion is cancelled.
If you want immediate permanent deletion, please request it at privacy@daysmate.com and it will be processed without delay.
제9조 (Automatic Data Collection (Cookies))
The Service uses only essential cookies to keep you signed in.
- Authentication cookies: Supabase authentication session tokens, used to keep you signed in
- Analytics and advertising cookies: not currently used. If introduced in the future, they will be implemented after separate notice and consent given at least 7 days before, in accordance with the amendment procedure of this policy (Article 12).
You can refuse cookies in your browser settings, but if you do, you may not be able to stay signed in.
제10조 (Privacy Officer)
Data subjects may direct any inquiries, complaints, or requests for relief regarding personal information protection arising from their use of the Service to the Privacy Officer, and the Service will respond to and handle such inquiries without delay.
제11조 (Remedies for Infringement of Rights)
If you need to report or consult about an infringement of personal information, you may contact the agencies below.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Investigation Division: 02-3480-3573
- National Police Agency Cyber Investigation Bureau: 182 (no area code)
제12조 (Changes to This Privacy Policy)
This Privacy Policy applies from the effective date. Where there are additions, deletions, or corrections to the content due to laws or policy, they will be announced through the Service starting at least 7 days before the changes take effect.
Effective date: 2026년 5월 15일