Privacy Policy
JAY X LAB (hereinafter referred to as "the Company") complies with the laws of the Republic of Korea, including the Personal Information Protection Act, and the personal information protection laws of the countries where members reside. To safely process members' personal information, the Company establishes the following Privacy Policy.
Effective Date: September 8, 2026 · Version: v2.0
1. Scope of Application and Compliant Laws
This Policy applies to the Company's website (jayxlab.com) and all services within it (automation, logo maker, detail page maker, etc.).
| Laws | Country/Region |
|---|---|
| Personal Information Protection Act (PIPA) · Information and Communications Network Act · Electronic Commerce Act | Republic of Korea |
| GDPR | EU / EEA |
| UK GDPR · Data Protection Act 2018 | United Kingdom |
| CCPA / CPRA | United States (California) |
| LGPD | Brazil |
| APPI | Japan |
| PIPEDA | Canada |
| Privacy Act 1988 | Australia |
2. Personal Information Collected and Collection Methods
We collect only the minimum information absolutely necessary to provide our services.
| Category | Item | Collection Method |
|---|---|---|
| Sign-up (Email) | Name, Nickname, Contact Info, Email, Country of Residence, Language/Currency Settings, Password (Encrypted Storage), Time of Consent to Terms, Privacy/Age Verification, Whether to Receive Marketing | Input on Sign-up Screen |
| Sign-up (Social) | Account identifier, Email, Name transmitted by the social provider (Google, Apple, Kakao, Naver) · Contact Info, Country, Consent entered later in «My Account» | Social Login |
| Paid Payment | Order Number, Product Name, Amount/Currency, Type of Payment Method, Approval Date and Time, Payment Agency Transaction Number (Payment method information such as card numbers is processed by the payment agency and is not stored by us) | Payment Screen |
| Service Usage | Settings for each service, data entered by the member and generated results, access tokens for external accounts (SNS, blogs, etc.) directly connected by the member | During service usage |
| Customer Inquiry | Name, email, inquiry content | Inquiry screen/email |
| Automatically Collected | Connection IP (hashed), browser/device information, access date and time, usage history, cookies | Automatically upon service usage |
3. Purpose of Use of Personal Information
-
Member Management: Identity verification, confirmation of intent to join, age verification, account protection, prevention of fraudulent use, delivery of notices
-
Service Provision: Provision of each service function, granting of subscriptions/use rights and limit management, payment processing, refunds, storage of transaction records
-
Customer Support: Response to inquiries, dispute resolution
-
Service Improvement: Analysis of usage statistics (in a form that does not identify individuals), error analysis
-
Marketing (for members who have consented only): Sending emails notifying of new services/benefits. You can opt out of receiving at any time via «My Account» or the link at the bottom of the email.
4. Retention Period of Personal Information
-
Members' personal information is destroyed without delay after 30 days (grace period) have passed following a withdrawal request. If you log in again within the grace period, the withdrawal will be cancelled.
-
However, in accordance with relevant laws and regulations, the following information is retained separately for a specified period.
| Items Retained | Period | Basis |
|---|---|---|
| Records of Contract/Withdrawal of Subscription | 5 years | Electronic Commerce Act |
| Records of Payment/Service Supply | 5 years | Electronic Commerce Act |
| Records of Consumer Complaint/Dispute Handling | 3 years | Electronic Commerce Act |
| Records of Labeling/Advertising | 6 months | Electronic Commerce Act |
| Access Records (Logs) | 3 months | Protection of Communications Secrets Act |
| Cookie Consent Records | 1 year | Information and Communications Network Act/GDPR Proof |
- Accounts that have not logged in for more than one year may be stored separately from other users' information in accordance with the Personal Information Protection Act, or deleted after 30 days' notice.
5. Provision of Personal Information to Third Parties
We do not provide members' personal information to third parties. However, exceptions apply if the member has separately consented or if there is a lawful request from investigative agencies or courts based on relevant laws.
6. Outsourcing of Personal Information Processing and Transfer Overseas
We outsource processing to the following operators for the operation of our services. Some operators process information overseas, and we ensure security through outsourcing contracts and standard contract clauses.
| Trustee | Outsourced Task | Country of Processing |
|---|---|---|
| Supabase Inc. | Database · Member Authentication Storage (Seoul Region) | South Korea |
| Vercel Inc. | Website Hosting · Distribution | Global Edge including the US |
| Resend Inc. | Sending Sign-up Confirmation · Password Reset Emails | US |
| Google LLC | Google Login, Automatic Translation, Visit Statistics (if agreed) | United States |
| Apple Inc. | Apple Login | United States |
| Kakao · Naver | Kakao · Naver Login | South Korea |
| PortOne · Toss Payments | Payment Processing · Payment Method Management | South Korea |
| Amazon Web Services | Email Sending (Backup Route) | United States |
Members may refuse international transfers; however, in this case, they may not be able to use the relevant features (e.g., Social Login, Email Verification).
7. Rights of Data Subjects and How to Exercise Them
Members (and their legal representatives) may exercise the following rights at any time.
-
Request for access, correction, deletion, or suspension of processing of personal information
-
Withdrawal of consent (including opt-out of marketing communications) and membership withdrawal
-
Request for transfer (download) of personal information
-
Request for explanation of automated decisions (if applicable)
Name, nickname, contact information, country, language, etc., can be directly modified or deleted in «My Account». For other requests, please email the Data Protection Officer listed below; we will process them within 10 days (within 1 month under GDPR) and notify you of the results. Legal representatives may exercise rights regarding the personal information of children under the age of 14 (or under 16 overseas).
8. Destruction of Personal Information
Personal information is destroyed without delay once the retention period ends or the purpose of processing is achieved. Electronic files are deleted using methods that render them unrecoverable, and paper documents are shredded or incinerated. Information subject to legal retention obligations is stored separately in a designated repository and destroyed in the same manner once the retention period expires.
9. Cookies and Visit Statistics
We use essential cookies for maintaining login status, language and currency settings, and saving consent, as well as analytic cookies (Google Analytics 4) that operate only when the member has consented. You can select these from the cookie banner on your first visit, or change them at any time in «Cookie Settings» at the bottom of the screen. For more details, please refer to the Cookie Policy.
10. Measures to Ensure the Security of Personal Information
-
Passwords are encrypted and stored in a way that makes them impossible to decrypt, and all communications are encrypted using TLS.
-
The database uses Row-Level Access Control (RLS) to ensure that only personal information can be accessed, and operator privileges are granted to the minimum number of personnel.
-
Payment method information is not stored on our servers but is processed by payment processing agencies based on PCI-DSS standards.
-
Access records are retained and managed to prevent tampering or forgery.
11. Additional Notice by Country/Region
Residents of the EU, EEA, and the UK (GDPR / UK GDPR): The legal grounds for our processing of personal information are: ① Fulfillment of contract (member management, provision of services, payment), ② Legal obligations (retention of transaction records), ③ Legitimate interests (security, prevention of fraud, service improvement), and ④ Consent (marketing, analytics cookies). Members have the right to object to processing or to file a complaint with the supervisory authority. The data manager is the same as the Chief Privacy Officer listed below.
Residents of California (CCPA/CPRA): We do not sell personal information or share it for targeted advertising purposes. Members have the right to know, the right to erasure, the right to rectification, and the right not to be discriminated against regarding collected information.
Residents of Brazil (LGPD), Japan (APPI), Canada (PIPEDA), and Australia: You may exercise the rights to access, rectify, delete, and portability as prescribed by each respective statute in the same manner as described in Section 7 above.
12. Chief Privacy Officer
| Item | Content |
|---|---|
| Manager | Jaeheon Lee (CEO) |
| Email | help@jayxlab.com |
| Phone | 070-8064-5778 |
| Address | Room 1105, 11F, Building 107, 113 Garam-ro, Paju-si, Gyeonggi-do |
13. Remedies for Infringement of Rights
You can contact the following organizations for reporting or consultation regarding personal information infringement.
-
Personal Information Infringement Report Center (privacy.kisa.or.kr · 118 without area code)
-
Personal Information Dispute Mediation Committee (kopico.go.kr · 1833-6972)
-
Supreme Prosecutors' Office Cyber Investigation Division (spo.go.kr · 1301 without area code)
-
National Police Agency Cyber Investigation Bureau (ecrm.police.go.kr · 182 without area code)
14. Changes to Policy
In the event of changes to this policy, notice will be posted on the website starting 7 days prior to the effective date. Significant changes to member rights, such as items collected, purposes, and retention periods, will be announced 30 days prior and also notified via email.
Addendum
-
This policy is effective from September 8, 2026.
-
The previous policy (v1.1, effective April 27, 2026) is replaced by this policy.