1. Controller, Scope, and Regional Rights
This Privacy Policy applies to personal data and service records processed by 쿼츠(Quartz) when providing Selltoss.
Selltoss may act as a controller for account, console, payment-status, security, and product-review processing. Sellers may act as separate controllers or businesses for their own store operations, customer support, refunds, tax handling, marketing, and seller-specific policies.
Depending on where you live, you may have rights under laws such as the GDPR or UK GDPR, Korea's Personal Information Protection Act, Japan's APPI, U.S. state privacy laws, and other local privacy laws. This Policy does not limit non-waivable rights under those laws.
2. Purposes of Processing
We process personal data only as needed for the following purposes:
- Account registration, login, workspace creation, and account security.
- Store setup, product listing, order creation, payment status confirmation, digital fulfillment, and receipt delivery.
- Discord, Telegram, and other channel commerce integrations and buyer notifications.
- Subscriptions, credits, fees, billing, settlement support, payment failure handling, and refund support.
- Product review, prohibited-product detection, fraud prevention, abuse prevention, access control, and security-event response.
- Support, incident investigation, dispute handling, compliance, and legal requests.
- Service quality improvement, feature analytics, and operational statistics.
3. Categories of Personal Data
Sellers and operators
- Email address, login-provider identifiers, account status, and access records.
- Workspace name, store name, subdomain, custom domain, country, timezone, language, and currency.
- Plan, credit balance and usage, subscription and payment records, and billing identifiers.
- Product, category, price, image, delivery method and content, coupon, theme, and email-template information.
- Discord or Telegram connection data, bot names, server, channel and chat identifiers, webhook status, and panel-message identifiers.
- Payment-method settings, SMTP settings, domain DNS status, and external-service connection status.
Buyers
- Email address, name, or display name entered at checkout.
- Order number, purchased product, quantity, price, currency, coupon, payment status, provider identifiers, receipt records, and order-status page access records.
- External user IDs, usernames, language, channel type, and message or notification delivery status needed for Discord or Telegram purchase flows.
Automatically collected and security data
- IP address, User-Agent, request URL, referrer, cookies, session identifiers, device and browser information, and access timestamps.
- Country, VPN, proxy, Tor, datacenter, or hosting-network signals used for access control and security.
- BotID, firewall, webhook signature verification, payment webhook, cron, error-log, and security-event records.
Support
- Support email, request content, attachments, conversation records, and handling records.
- Order, payment, store, and channel-connection information provided by users for troubleshooting.
4. Legal Bases
- Performance of a contract, including account access, orders, payments, receipts, and digital fulfillment.
- Legitimate interests, including fraud prevention, platform security, service reliability, dispute handling, and protection of users and Selltoss.
- Legal obligations, including ecommerce, tax, accounting, communications, privacy, sanctions, and lawful government or rights-holder requests.
- Consent, where required for marketing, optional features, cookies that are not strictly necessary, or certain integrations.
- Seller onboarding uses separate required actions for accepting the Terms and acknowledging the Privacy Policy. Optional or marketing consent is not bundled into either action.
- Evidence includes document versions, user and workspace identifiers, locale, server timestamp, country code, and User-Agent. Onboarding and evidence are committed in one database transaction; if the evidence write fails, no workspace or store is created.
5. Retention
- Account, profile, workspace, and store settings: until account or workspace deletion. Minimal email and login-provider identifiers may be segregated and retained for 1 year after closure to prevent duplicate or abusive re-registration.
- Contracts and withdrawal records: 5 years; payment and supply records: 5 years; consumer complaints and dispute records: 3 years; display and advertising records: 6 months, as required by Korean ecommerce law.
- Terms acceptance and Privacy Policy acknowledgement evidence: 5 years after the relevant agreement ends. Only evidence needed to establish the agreement or resolve a dispute is retained.
- Support records: 3 years after closure; general request and security logs: 3 months. Records segregated for an abuse, security, payment, or infringement case may be kept for up to 3 years after the case closes.
- A lawful preservation request or pending investigation, claim, or dispute extends retention only for the minimum data and period necessary.
6. Third-Party Provision
We do not sell personal data. We provide it only to the relevant store seller for order performance, to a payment or messaging provider visibly selected for the transaction, where the user separately agrees, or where law requires it.
- Relevant store seller — buyer name, email, order, item, amount, payment and delivery status; purpose: performance, delivery, support, withdrawal, refund, and dispute handling; retention: the seller's applicable statutory period or until the purpose ends.
- Selected payment or messaging provider — minimum order, payment, email, and external-user identifiers needed for payment status or message delivery; retention: the provider's legal obligations and published policy. Refusal prevents use of that provider or channel.
- Authorities, courts, or rights holders — only the minimum necessary where a valid warrant, order, legal duty, or other lawful basis applies.
7. Processors and International Transfers
We contractually manage processors for purpose limitation, security, subprocessors, and deletion. International transfers occur when a feature is used over TLS, based on contract performance, law, or consent as applicable. Users may refuse by not using an optional feature or closing the account, but essential infrastructure cannot then provide the relevant service.
Core infrastructure
- Supabase, Inc. (United States) — database, authentication, and storage. Account and authentication identifiers, store, product, order, legal-evidence, and support data are transferred continuously during service use. Primary data is stored in the selected Seoul, South Korea region; Supabase and its published subprocessors may have limited U.S. support and operational access. Retained for the agreement, until an earlier deletion request, or statutory expiry. [email protected] / https://supabase.com/legal/dpa.
- Vercel Inc. (United States) — hosting, functions, deployment, error, and security processing. IP, URL, headers, device/access data, function inputs and outputs, and error logs are transferred on access or function execution to the South Korea function region, Vercel's primary U.S. facilities, and published subprocessor locations. Processed for the agreement or until deletion instructions and legal retention end. [email protected] / https://vercel.com/legal/dpa.
- Cloudflare, Inc. (United States) — DNS, CDN, WAF, DDoS, and bot protection. IP, URL, headers, device/network signals, and security events are processed on access in Cloudflare's network near the visitor, including South Korea, and in U.S. operating systems. Customer logs are deleted after the plan- and feature-specific period; segregated security-case records are kept only as needed. [email protected] / https://www.cloudflare.com/policies/privacy/.
Feature providers
- Plus Five Five, Inc. (Resend, United States) — sender/recipient email, name, subject, body, and delivery status are transferred to Resend and its published U.S. subprocessors when an order or operational email is sent. Retained as needed to provide delivery, meet law, resolve disputes, or process deletion. [email protected] / https://resend.com/legal/privacy-policy.
- Google LLC (Gemini Developer API, United States) — product name, description, image, variant names, and seller country code are transferred to U.S. processing facilities when a product is saved. Custom analytics sends the submitted request, permitted metric descriptions, and saved analysis names and definitions from the same store to compose or reuse an analysis; raw buyer/order records and aggregate results are not sent to the analytics model. Standard abuse-monitoring logs may be kept for up to 55 days; approved Zero Data Retention removes identifiable inputs and outputs from those logs. Paid services do not use prompts or responses for product improvement, while free-service or voluntary data-sharing settings follow Google's applicable terms. Selltoss does not use grounding, File API, or explicit caching. https://ai.google.dev/gemini-api/docs/zdr.
- Proxycheck.io (servers in Canada, the United Kingdom, Germany, Finland, Poland, and Singapore) — visitor IP is transferred when VPN, proxy, Tor, or hosting detection runs. Selltoss sends tag=0 on every lookup, so Proxycheck.io does not retain the submitted raw IP in query history and records only that a query occurred and its result type. Selltoss stores a keyed hash rather than the raw IP with the limited risk result. https://proxycheck.io/contact/ / https://proxycheck.io/gdpr/.
- Polar Software, Inc. (United States; subprocessors in the United States, United Kingdom, and distributed Vercel regions) — seller email, seller-account identifier, plan, product, checkout, order, subscription, and billing identifiers are transferred during Selltoss credit or subscription purchase. Retained for the transaction relationship and applicable payment, tax, accounting, and dispute periods. [email protected] / https://polar.sh/legal/sub-processors.
- Discord Inc. (United States) — Discord user, application, server, and channel IDs, username, language, and order notification content are transferred to U.S. servers when a seller connects or uses Discord commerce. Retained until deletion or until the service purpose and legal duties end under Discord policy. [email protected] / https://discord.com/privacy.
- Telegram Messenger Inc. (Netherlands for UK/EEA sign-ups; encrypted distributed data centers for others) — user, bot, chat, and message IDs, username, language, and order notification content are transferred when Telegram commerce is connected or used. Cloud messages remain until deletion or the service purpose ends; security metadata may be retained for up to 12 months. https://telegram.org/support / https://telegram.org/privacy.
- Seller-connected SMTP provider — recipient/sender email, name, order/fulfillment content, and delivery status are sent to the server and country selected by the seller when mail is sent. The seller must disclose that provider, country, and retention under its own contract and privacy notice.
Seller-selected payment providers
- NOWPayments Ltd. (Seychelles) — order identifier and description, amount, currency, crypto asset, callback URL, and payment status are transferred when crypto payment is created or queried; retained as needed for transactions, security, AML, law, and disputes. https://nowpayments.io/doc/privacy-policy.pdf.
- Stripe, LLC (United States) or Stripe Technology Company Limited (Ireland) — buyer email, order identifier, product description, amount, currency, payment, and fraud-prevention data are transferred when card checkout is created or processed. Processing may occur in the U.S., Ireland, India, and payment/financial-partner countries; Stripe generally may retain transaction or relationship data for five years or longer. https://stripe.com/legal/privacy-center.
- PayPal, Inc. (United States) and the buyer's regional PayPal entity — order identifier, product description, amount, currency, payment status, and account/payment details supplied directly by the buyer are processed on order creation, approval, capture, or lookup. Data may be transferred to the U.S. and PayPal or financial-partner countries and retained under regional law and PayPal policy. https://www.paypal.com/privacy.
- Mollie B.V. (Netherlands) — order identifier, product description, amount, currency, redirect/webhook URLs, and payment status are processed on payment creation or lookup in the Netherlands, EEA, and safeguarded subprocessor countries, until statutory financial retention or purpose completion. https://www.mollie.com/legal/privacy.
- Cash App manual transfer is not an API transfer of buyer payment details by Selltoss. The buyer pays the seller's published $Cashtag directly, under the seller's and Block, Inc.'s (United States) privacy terms.
8. Cookies and Similar Technologies
- We may use cookies and similar technologies for login, session security, language settings, store access control, purchase-flow continuity, and service improvement.
- You can block or delete cookies through your browser settings. Some required cookies are necessary for login, checkout, dashboard, and security features.
- For security, abuse prevention, and access control, the service may automatically process IP, country, VPN, proxy, Tor, datacenter, and browser signals.
9. Automated Processing and AI Review
- When a product is created or edited, rule-based filters and Google Gemini analyze its name, description, image, delivery-related text, and seller operating country. A prohibited result blocks saving and records a reason and violation category.
- Repeated violations may automatically restrict a store. AI errors or indeterminate responses may fail open, so review does not guarantee legality or safety.
- A person materially affected by an automated result may request an explanation, objection, and human review at [email protected] or [email protected].
10. Your Rights
- Depending on your location and the legal basis for processing, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent.
- EU/UK users may have rights to access, rectification, erasure, restriction, portability, objection, consent withdrawal, and complaint to a supervisory authority.
- Korean users may have rights to access, correction, deletion, suspension of processing, withdrawal of consent, and remedies through relevant Korean authorities.
- Japanese users may have rights to request notification of purpose of use, disclosure, correction, suspension of use, and disclosure of third-party provision records for retained personal data.
- Users in some U.S. states may have rights to access, delete, correct, port, opt out of sale or sharing, or limit sensitive personal information.
- Requests may be sent to the contact address in this Policy. We may need to verify your identity and may retain certain data where required for legal, security, payment, or dispute reasons.
11. Children
- The service is not directed to children under 14 or under the digital-consent age that applies in the user's jurisdiction.
- If we learn that we collected a child's personal data without required consent, we will delete it or take other appropriate steps.
12. Security
- HTTPS and encryption in transit.
- Authentication, session, and access-right controls.
- Secret storage or encryption for payment credentials, bot tokens, SMTP passwords, and other sensitive settings.
- Least-privilege operational access.
- Webhook signature checks, security logs, firewall controls, BotID, and abuse-prevention measures.
- Incident monitoring, backup, and recovery procedures.
13. Complaints and Remedies
You may contact us first, and you may also contact the privacy regulator, consumer protection body, or other authority in your country or region if you believe your rights were violated.
14. Privacy Contact
- Privacy Officer: 김연준
- Email: [email protected]
- Phone: 010-4081-9904
- Use this contact for privacy requests, complaints, objections to automated outcomes, and questions about international transfers.
15. Changes
We may update this Policy when laws, service features, providers, processing purposes, or data categories change. We will provide appropriate notice before material changes take effect.
16. Destruction Procedure and Method
- When the purpose or retention period ends, we identify data for deletion under the Privacy Officer's oversight after segregating only data subject to a legal hold or statutory retention requirement.
- Retained data is logically separated from active service data and access is limited to personnel who need it for the stated purpose.
- Electronic records are securely deleted so they are not reasonably recoverable. Backups expire through the backup rotation while inaccessible for ordinary use, and encryption keys may be destroyed where appropriate. Paper records are shredded or incinerated.