PRIVACY POLICY
개인정보 처리방침
개정 안내 — 2026년 10월 9일부터 개정 방침이 시행됩니다. 문서 전체를 새 구조로 정리했습니다: 항목·목적·보유기간을 한곳에 모으고, 국외 이전 국가·시기·방법, 파기 절차, 안전성 확보 조치, 권익침해 구제 방법을 추가했습니다. 수집하는 정보는 늘지 않았습니다.
1. 처리하는 개인정보와 목적·보유기간
디자인 만들기
- 항목
- 브랜드명·업종·스타일, 로고 이미지
- 목적
- 시안 생성
- 보유기간
- 서버에 저장하지 않음(AI 요청에만 사용)
최종 디자인·결제 요청
- 항목
- 이름·직함·전화번호·이메일·SNS 계정(명함에 인쇄되는 값), 결제 수신 이메일, 명함 디자인 파일, 로고 이미지, 결제 식별 정보
- 목적
- 결과물 제공, 다시 받기 링크 발송, 문의 대응
- 보유기간
- 결제 요청일부터 90일, 이후 순차 파기(결제를 끝내지 않은 요청 포함)
로그인 링크 요청
- 항목
- 이메일 주소
- 목적
- 로그인 링크 발송
- 보유기간
- 링크 만료(15분) 뒤 다음 요청을 처리할 때 삭제
회원
- 항목
- 계정 이메일, 가입일, 약관 동의 시각·버전, 언어 설정, 세션 쿠키(tda_session)
- 목적
- 로그인 유지, 계정 관리, 안내 메일 언어
- 보유기간
- 탈퇴 시 즉시 삭제(세션 쿠키는 최대 30일, 로그아웃 시 삭제)
회원 보관함
- 항목
- 명함 디자인 파일(연락처 포함), 로고 이미지, vCard 연락처, 결제 여부
- 목적
- 보관함 제공
- 보유기간
- 직접 삭제하거나 탈퇴하면 즉시 삭제
이메일 변경
- 항목
- 새 이메일 주소, 확인 링크 기록
- 목적
- 본인 확인 후 변경
- 보유기간
- 만료(15분)되거나 사용된 뒤 다음 요청 때 삭제
Pro 구독
- 항목
- 구독 상태(활성 여부·다음 결제일·해지 예약 여부), Pro 혜택 이용 기록(무료 한도를 넘는 보관·결제하지 않은 명함 다운로드·공유 링크를 처음 만든 시각)
- 목적
- 구독 관리, 환불 판단(환불규정 제4조)
- 보유기간
- 탈퇴 시 즉시 삭제
공유 링크
- 항목
- 공유용 명함 앞면 이미지(연락처가 보일 수 있음), 공유 주소
- 목적
- 공유 링크 제공
- 보유기간
- 공유 중지·명함 삭제·탈퇴 시 즉시 삭제(Pro 구독이 끝나면 링크는 열리지 않지만, 다시 구독할 때를 위해 위 시점까지 보관)
문의
- 항목
- 이름, 이메일 주소, 문의 내용
- 목적
- 답변
- 보유기간
- 답변과 이력 확인을 위해 보관, 삭제를 요청하면 지체 없이 삭제
자동 생성
- 항목
- 접속 IP 주소·이메일의 해시값(원본 IP 주소는 저장하지 않음)
- 목적
- 남용 방지
- 보유기간
- 1시간(디자인 생성) 또는 10분(로그인 링크·이메일 변경 요청)이 지난 뒤 다음 요청 때 삭제
자동 수집(이용 분석)
- 항목
- 방문한 페이지, 클릭·스크롤 기록, 기기·브라우저 정보, 대략적인 지역(국가·도시), 분석 쿠키
- 목적
- 이용 통계, 화면 개선
- 보유기간
- 각 업체의 보관 기간 설정에 따름
이용자 기기
- 항목
- 언어 설정, 결과물을 다시 불러오기 위한 디자인 데이터·로고 이미지·결제 수신 이메일(브라우저 localStorage)
- 목적
- 결제 후 결과물 복원
- 보유기간
- 이용자 기기에만 저장 — 브라우저 데이터를 지우면 삭제
- 만 14세 미만 아동의 개인정보는 수집하지 않으며, 로그인(가입)은 만 14세 이상만 할 수 있습니다.
- 카드 번호 등 결제 정보는 결제 대행사(Polar)가 처리하며 서비스는 받지 않습니다.
- 보유기간이 지나면 결과물을 다시 받을 수 없으니 받으신 파일은 기기에 보관해 주세요.
2. 개인정보의 제3자 제공
- 결제 처리를 위해 Polar에 이메일 주소와 결제 정보를 제공합니다. 그 밖에는 이용자의 동의 없이 제3자에게 제공하지 않습니다.
- Pro 회원이 공유 링크를 만들면, 링크를 가진 누구나 명함 앞면 이미지와 명함에 적힌 연락처(이름·직함·전화번호·이메일·SNS 계정)를 볼 수 있습니다. 회원이 직접 선택한 공개이며, 공유 링크는 검색엔진에 노출되지 않도록 설정되어 있습니다.
3. 처리 위탁과 국외 이전
서비스는 아래 업체에 개인정보 처리를 맡기며, 이 중 국외 업체에는 서비스 이용 과정에서 네트워크로 정보가 전송됩니다.
Cloudflare, Inc.
- 국가·위치
- 미국 법인 — 데이터베이스는 아시아·태평양 지역에서 운영, 웹사이트는 전 세계 데이터센터에서 제공
- 항목
- 주문·계정·보관함·공유 링크 정보
- 목적
- 웹사이트 호스팅, 데이터 저장
- 시기·방법
- 서비스 이용 시 네트워크로 전송
- 보유기간
- 1절의 보유기간
Google (Gemini API)
- 국가·위치
- 미국 등 Google이 시설을 둔 국가
- 항목
- 브랜드명·업종·스타일·로고 이미지, 최종 단계에서는 이름·직함·연락처·이메일·SNS 계정
- 목적
- AI 명함 시안·최종 디자인 생성
- 시기·방법
- 디자인을 요청할 때, 서비스의 중계 서버(Vercel)를 거쳐 전송
- 보유기간
- Google 약관에 따름(정책 위반 감시 목적으로 최대 55일 보관)
Vercel Inc.
- 국가·위치
- 미국 법인 — 중계 서버는 서울 리전에서 실행
- 항목
- 위 Gemini API 요청 내용
- 목적
- AI 요청 중계
- 시기·방법
- 디자인을 요청할 때
- 보유기간
- 저장하지 않음(전달만 함)
Polar Software Inc.
- 국가·위치
- 미국·캐나다 (카드 정보는 Stripe, Inc.가 처리)
- 항목
- 이메일 주소, 결제 정보, 회원 식별번호(로그인 회원의 구독)
- 목적
- 결제 처리, 구독 관리
- 시기·방법
- 결제할 때
- 보유기간
- Polar 개인정보처리방침에 따름
Plus Five Five, Inc. (Resend)
- 국가·위치
- 미국
- 항목
- 이메일 주소, 브랜드명(결과물 링크 메일 본문), 주문번호
- 목적
- 로그인 링크·이메일 변경 확인·변경 알림·결과물 링크 메일 발송
- 시기·방법
- 메일을 보낼 때
- 보유기간
- Resend 개인정보처리방침에 따름
Formspree, Inc.
- 국가·위치
- 미국 등 Formspree가 운영하는 국가
- 항목
- 이름, 이메일 주소, 문의 내용
- 목적
- 문의 접수
- 시기·방법
- 문의를 보낼 때
- 보유기간
- Formspree 개인정보처리방침에 따름(삭제 요청 시 지체 없이 삭제)
Google LLC (Google Analytics)
- 국가·위치
- 미국 등 전 세계 데이터센터
- 항목
- 방문·이용 기록, 기기·브라우저 정보, 분석 쿠키
- 목적
- 이용 통계 분석
- 시기·방법
- 페이지를 방문할 때
- 보유기간
- Google 보관 기간 설정에 따름
Microsoft Corporation (Clarity)
- 국가·위치
- 미국 (Microsoft Azure 클라우드)
- 항목
- 클릭·스크롤 기록, 화면 재생 기록, 기기·브라우저 정보, 분석 쿠키
- 목적
- 화면 이용 분석
- 시기·방법
- 페이지를 방문할 때
- 보유기간
- Microsoft 정책에 따름(화면 재생 기록 기본 30일)
Google LLC (Google Fonts) · Volentio JSD Limited (jsDelivr) · IMG.LY GmbH
- 국가·위치
- 미국·영국·독일 (각 업체의 전 세계 전송망)
- 항목
- 접속 정보(IP 주소, 브라우저 정보) — 로고 이미지는 보내지 않고 이용자 기기 안에서 처리
- 목적
- 글꼴·화면 라이브러리·로고 배경 제거 모델 파일 제공
- 시기·방법
- 페이지를 열거나 로고를 올릴 때
- 보유기간
- 각 업체 정책에 따름
- 국외 이전을 원하지 않으면 서비스 이용을 중단하거나 문의처로 삭제를 요청할 수 있습니다. 다만 위 업체 없이는 서비스를 제공할 수 없습니다.
- 공유 화면의 인증 표시(Q장)에는 고정 문구와 참조번호만 보내며 개인정보는 보내지 않습니다.
4. 파기 절차와 방법
- 보유기간이 끝나거나 처리 목적을 이루면 파기합니다. 회원 정보·보관함·공유 링크처럼 이용자가 삭제하는 정보는 그 즉시 삭제합니다.
- 전자 파일은 데이터베이스에서 삭제해 복구할 수 없게 합니다. 종이 문서로는 보관하지 않습니다.
- 결제 주문 기록은 90일이 지나면 더 이상 열람·재발송되지 않으며, 새 주문이 처리될 때 함께 삭제됩니다.
5. 이용자의 권리와 행사 방법
- 이용자는 언제든 자신의 개인정보 열람·정정·삭제·처리정지를 요구할 수 있습니다.
- 회원은 마이페이지에서 이메일·언어를 바꾸고, 보관함의 명함을 지우고, 탈퇴할 수 있습니다. 탈퇴하면 계정·보관함·공유 링크가 즉시 삭제됩니다. 결제 주문 기록은 탈퇴와 별개로 1절의 90일 기준을 따릅니다.
- 그 밖의 요청(게스트 주문 정보 삭제 등)은 문의하기로 접수해 주시면 본인 확인 뒤 지체 없이 처리합니다.
6. 안전성 확보 조치
- 모든 통신은 HTTPS로 암호화합니다.
- 로그인 링크·세션·이메일 변경 확인 링크는 원문이 아닌 해시값만 저장하며, 남용 방지용 IP 주소와 이메일도 해시값만 저장합니다.
- 데이터베이스는 공개 주소나 접속 키 없이 서비스 서버만 접근할 수 있습니다.
- 결제 결과물은 결제 때 만든 회수 토큰이 있어야만 열 수 있고, 보관함은 로그인한 본인만 볼 수 있습니다.
- 개인정보는 필요한 기간만 보관하고, 정해진 기간이 지나면 파기합니다.
7. 쿠키 등 자동 수집 장치
- 필수 쿠키 tda_session: 로그인 유지에 씁니다. 차단하면 로그인할 수 없습니다.
- 분석 쿠키(Google Analytics·Microsoft Clarity): 브라우저 설정에서 쿠키를 차단하거나 Google이 제공하는 차단 부가기능(tools.google.com/dlpage/gaoptout)을 설치해 거부할 수 있으며, 거부해도 이용에 제한이 없습니다.
8. 개인정보 보호책임자와 문의처
- 개인정보 보호책임자: 서비스 운영자. 개인정보 관련 문의·불만·피해 구제 요청은 문의하기로 접수해 주세요.
9. 권익침해 구제 방법
개인정보 침해에 대한 상담·신고는 아래 기관에 할 수 있습니다.
- 개인정보분쟁조정위원회: 1833-6972 (www.kopico.go.kr)
- 개인정보침해신고센터: 118 (privacy.kisa.or.kr)
- 대검찰청: 1301 (www.spo.go.kr)
- 경찰청: 182 (ecrm.police.go.kr)
10. 처리방침의 변경
이 처리방침을 바꿀 때는 시행 7일 전부터 서비스 화면에 공지합니다.
시행일: 2026년 10월 9일 (종전 2026년 9월 24일)
PRIVACY POLICY
Privacy Policy
Notice of changes — The revised Policy takes effect on October 9, 2026. The whole document has been reorganized: data, purposes and retention are now in one place, and we added the countries, timing and method of overseas transfers, the destruction procedure, security measures and remedies. We do not collect any additional data.
1. Personal Data We Process, Purposes and Retention
Creating designs
- Data
- Brand name, industry, style, logo image
- Purpose
- Creating concepts
- Retention
- Not stored on our servers (used only for the AI request)
Final design and payment request
- Data
- Name, title, phone, email and social accounts (the values printed on the card), delivery email, card design files, logo image, payment identifiers
- Purpose
- Providing deliverables, sending the download link, answering inquiries
- Retention
- 90 days from the payment request, then deleted progressively (including unfinished payment requests)
Sign-in link request
- Data
- Email address
- Purpose
- Sending the sign-in link
- Retention
- Deleted when the next request is processed after the link expires (15 minutes)
Members
- Data
- Account email, sign-up date, time and version of consent to the Terms, language setting, session cookie (tda_session)
- Purpose
- Keeping you signed in, account management, email language
- Retention
- Deleted immediately when you delete your account (the session cookie lasts up to 30 days and is removed on sign-out)
Member archive
- Data
- Card design files (including contact details), logo image, vCard contact, payment status
- Purpose
- Providing the archive
- Retention
- Deleted immediately when you delete it or your account
Email change
- Data
- New email address, record of the confirmation link
- Purpose
- Changing the email after verification
- Retention
- Deleted with the next request after it expires (15 minutes) or is used
Pro subscription
- Data
- Subscription status (active, next billing date, scheduled cancellation), record of Pro benefit use (storage beyond the free limit, downloading unpaid cards, the time a share link was first created)
- Purpose
- Subscription management, refund decisions (Refund Policy Article 4)
- Retention
- Deleted immediately when you delete your account
Share links
- Data
- Card front image used for sharing (contact details may be visible), share address
- Purpose
- Providing share links
- Retention
- Deleted immediately when you stop sharing, delete the card or delete your account (if your Pro subscription ends, the link stops opening but is kept until then in case you resubscribe)
Inquiries
- Data
- Name, email address, message
- Purpose
- Replying
- Retention
- Kept for replies and history; deleted without delay on request
Generated automatically
- Data
- Hashes of IP addresses and emails (original IP addresses are not stored)
- Purpose
- Preventing abuse
- Retention
- Deleted with the next request after 1 hour (design creation) or 10 minutes (sign-in links and email-change requests)
Collected automatically (analytics)
- Data
- Pages visited, clicks and scrolling, device and browser information, approximate location (country, city), analytics cookies
- Purpose
- Usage statistics, improving pages
- Retention
- According to each provider’s retention settings
Your device
- Data
- Language setting; design data, logo image and delivery email for restoring deliverables (browser localStorage)
- Purpose
- Restoring deliverables after payment
- Retention
- Stored only on your device — removed when you clear browser data
- We do not collect personal data from children under 14, and only people 14 or older can sign in.
- Card numbers and other payment details are handled by our payment provider (Polar); the Service does not receive them.
- After the retention period you can no longer get the deliverables again, so please keep the files you downloaded.
2. Provision to Third Parties
- We provide your email address and payment information to Polar to process payments. Otherwise we do not provide personal data to third parties without your consent.
- When a Pro member creates a share link, anyone with the link can see the card front image and the contact details on the card (name, title, phone, email, social accounts). This is a disclosure the member chooses, and share links are set not to appear in search engines.
3. Processors and Overseas Transfers
We entrust the processing of personal data to the providers below. For providers outside Korea, data is transmitted over the network as you use the Service.
Cloudflare, Inc.
- Country / location
- US company — database operated in the Asia-Pacific region; website served from data centers worldwide
- Data
- Order, account, archive and share-link data
- Purpose
- Website hosting, data storage
- When and how
- Transmitted over the network as you use the Service
- Retention
- The retention periods in Section 1
Google (Gemini API)
- Country / location
- The US and other countries where Google has facilities
- Data
- Brand name, industry, style and logo image; at the final step, name, title, contact details, email and social accounts
- Purpose
- Creating AI card concepts and final designs
- When and how
- When you request a design, sent via our relay server (Vercel)
- Retention
- Per Google’s terms (kept up to 55 days for abuse monitoring)
Vercel Inc.
- Country / location
- US company — the relay server runs in the Seoul region
- Data
- The Gemini API request contents above
- Purpose
- Relaying AI requests
- When and how
- When you request a design
- Retention
- Not stored (relayed only)
Polar Software Inc.
- Country / location
- US and Canada (card details are handled by Stripe, Inc.)
- Data
- Email address, payment information, member ID (for signed-in members’ subscriptions)
- Purpose
- Payment processing, subscription management
- When and how
- When you pay
- Retention
- Per Polar’s privacy policy
Plus Five Five, Inc. (Resend)
- Country / location
- US
- Data
- Email address, brand name (in the download-link email), order number
- Purpose
- Sending sign-in, email-change confirmation and notice, and download-link emails
- When and how
- When an email is sent
- Retention
- Per Resend’s privacy policy
Formspree, Inc.
- Country / location
- The US and other countries where Formspree operates
- Data
- Name, email address, message
- Purpose
- Receiving inquiries
- When and how
- When you submit an inquiry
- Retention
- Per Formspree’s privacy policy (deleted without delay on request)
Google LLC (Google Analytics)
- Country / location
- The US and data centers worldwide
- Data
- Visit and usage records, device and browser information, analytics cookies
- Purpose
- Usage statistics
- When and how
- When you visit a page
- Retention
- Per Google’s retention settings
Microsoft Corporation (Clarity)
- Country / location
- US (Microsoft Azure cloud)
- Data
- Clicks, scrolling, session replays, device and browser information, analytics cookies
- Purpose
- Page usage analysis
- When and how
- When you visit a page
- Retention
- Per Microsoft’s policy (session replays kept 30 days by default)
Google LLC (Google Fonts) · Volentio JSD Limited (jsDelivr) · IMG.LY GmbH
- Country / location
- US, UK and Germany (each provider’s worldwide delivery network)
- Data
- Connection data (IP address, browser information) — your logo image is not sent; it is processed on your device
- Purpose
- Serving fonts, page libraries and the logo background-removal model files
- When and how
- When you open a page or upload a logo
- Retention
- Per each provider’s policy
- If you do not want your data transferred overseas, you may stop using the Service or ask us to delete your data through the Contact page. Note that we cannot provide the Service without these providers.
- For the verification badge (Q-temp) on share pages, we send only fixed text and a reference number — no personal data.
4. Destruction Procedure and Method
- We destroy personal data once the retention period ends or the purpose has been achieved. Data you delete yourself — such as your account, archive and share links — is deleted immediately.
- Electronic records are deleted from the database so they cannot be recovered. We do not keep paper records.
- Order records older than 90 days can no longer be opened or resent, and are deleted as new orders are processed.
5. Your Rights and How to Exercise Them
- You may request access to, correction, deletion or suspension of processing of your personal data at any time.
- Members can change their email and language, delete cards from the archive and delete their account on My Page. Deleting your account immediately removes your account, archive and share links. Order records follow the 90-day rule in Section 1 regardless of account deletion.
- For other requests (such as deleting guest order data), contact us through the Contact page; we handle them without delay after verifying your identity.
6. Security Measures
- All connections are encrypted with HTTPS.
- We store only hashes — not the originals — of sign-in links, sessions and email-change links, and only hashes of IP addresses and emails used to prevent abuse.
- The database has no public address or access key; only the Service’s servers can reach it.
- Deliverables can be opened only with the recovery token created at payment, and an archive can be seen only by the signed-in member who owns it.
- We keep personal data only as long as needed and destroy it when the set period ends.
7. Cookies and Automatic Collection
- Essential cookie tda_session: keeps you signed in. If you block it, you cannot sign in.
- Analytics cookies (Google Analytics, Microsoft Clarity): you can refuse them by blocking cookies in your browser or installing Google’s opt-out add-on (tools.google.com/dlpage/gaoptout). Refusing does not limit your use of the Service.
8. Privacy Officer and Contact
- Privacy officer: the operator of the Service. Please send privacy questions, complaints or requests for remedies through the Contact page.
9. Remedies for Infringement
You can seek advice or report a privacy infringement to the following Korean authorities:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
10. Changes to This Policy
When we change this Policy, we announce it on the Service at least 7 days before it takes effect.
Effective Date: October 9, 2026 (previously September 24, 2026)