Cheiz Privacy Policy

LIFESHOT.Inc (hereinafter the 'Company') complies with the Personal Information Protection Act (개인정보 보호법) and other relevant laws to lawfully process personal information and manage it safely, in order to protect the freedom and rights of data subjects. Pursuant to Article 30 of the Personal Information Protection Act, the Company hereby establishes and discloses the following Privacy Policy in order to inform data subjects of the procedures and standards for the processing of personal information and to handle related grievances promptly and smoothly.

Article 1. Items, Purposes of Processing, and Retention Period of Personal Information

1. The Company processes the personal information of data subjects as follows. The personal information being processed shall not be used for purposes other than those stated below, and if the purpose of use is changed, the Company will take necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.

1) Information collected at the time of photo shoots

  • Items collected: Information collected from general members - photographs taken
  • Purpose of collection: Smooth provision of the photo shoot service, and training and improvement of AI photo-retouching models
  • Retention period: Until the member withdraws membership or requests deletion. Photographs taken are retained so that users may view and purchase them again at any time, and to train and improve our AI photo-retouching models. Users may request deletion at any time through customer support, and the data is destroyed without delay upon such request.

2) Information collected at the time of service sign-up

  • Items collected: General members - email, password, nickname, whether under the age of 14 / Photographer members - photographer alias, photographer real name, contact, email, whether under the age of 14
  • Purpose of collection: Member identification and confirmation of intent to sign up; verification of whether the user is 14 years of age or older to prevent service use by children under 14; maintenance and management of member status; prevention and sanctioning of acts that hinder the smooth operation of the service (including account theft and fraudulent use)
  • Retention period: Until the member withdraws membership

3) Information collected when creating a 'folder' within the service

  • Items collected: Mobile phone number, photo for identification
  • Purpose of collection: Verification of the photo recipient; collection of contact for consultation regarding service contents at the time of photo delivery
  • Retention period: Until the member withdraws membership or requests deletion

4) Information collected at the time of paid service payment

  • Items collected: Name, phone number, email address
  • Purpose of collection: Identification and authentication for the provision of paid services; issuance of contracts and invoices and settlement of fees for paid services
  • Retention period: 5 years pursuant to the Act on Consumer Protection in Electronic Commerce (전자상거래법)

5) Information collected during customer consultation (KakaoTalk channel)

  • Items collected: Cheiz registration email, Cheiz nickname, payment order number, device model in use
  • Purpose of collection: Handling of inquiries or complaints
  • Retention period: 3 years pursuant to the Act on Consumer Protection in Electronic Commerce (전자상거래법)

2. The Company may collect additional personal information with the consent of users in order to provide a variety of customer experiences.

1) Information collected upon winning a Cheiz-hosted event

  • Items collected: For shipped goods - name, address, phone number / For mobile goods - mobile phone number
  • Retention period: 3 months after the end of the event

3. The Company receives personal information of customers from third parties in the following situations in order to provide services smoothly.

1) Payment for paid services

  • Provider: Stripe
  • Items received: Name, phone number, email address, credit card number, card issuer, order number
  • Purpose of receipt: Prevention of fraudulent use through identity verification
  • Retention period: Until the purpose of collection and use is achieved. However, mandatory collection items are retained for 5 years pursuant to the Act on Consumer Protection in Electronic Commerce (전자상거래법).

4. Automatically generated information such as visit date and time may be automatically generated and collected during the use of the app.

Article 2. Processing and Retention Period of Personal Information under Law

The Company processes and retains personal information within the retention and use period under relevant laws or the retention and use period agreed to at the time of collection from the data subject. When the purpose of collection and use has been achieved, the collected personal information is safely destroyed. However, the following information is retained for the period specified below for the reasons set forth in the relevant laws.

Retention itemLegal basisRetention period
Records related to contracts or withdrawal of subscriptionsAct on Consumer Protection in Electronic Commerce5 years
Records related to payment and supply of goods, etc.Act on Consumer Protection in Electronic Commerce5 years
Records related to consumer complaints or dispute handlingAct on Consumer Protection in Electronic Commerce3 years
Records related to display/advertisingAct on Consumer Protection in Electronic Commerce6 months
Service visit recordsProtection of Communications Secrets Act3 months

Article 3. Provision and Outsourcing of Personal Information

  1. The Company does not provide users' personal information to external parties without prior consent. However, personal information is provided only in the following cases: when the user has directly consented to the provision of personal information for the use of an external partner's services; when the Company is obligated to submit personal information under relevant laws; or when imminent danger to the user's life or safety is identified and such provision is necessary to resolve it.
  2. The Company outsources some of the work necessary for service provision to external companies, and stipulates necessary matters and supervises and manages the outsourced companies so that they handle personal information safely in accordance with the Personal Information Protection Act. If the user does not use the services related to the outsourced work, the user's personal information will not be provided to the outsourced company.
ProcessorEntrusted work
PlanetScale, Inc.Database hosting and operation
Amazon Web Services, Inc.Photograph storage and server operation
Cloudflare, Inc.Photograph storage and delivery
Vercel Inc.Service application hosting
Upstash, Inc.Login protection and authentication session management
Stripe, Inc.Electronic payment services
Twilio Inc. (SendGrid)Email delivery
Google LLCApp push notifications, social login authentication and AI photo retouching (Gemini)
Apple Inc.Social login authentication
Kakao Corp.Social login authentication and customer support (located in the Republic of Korea)

Article 4. Cross-Border Transfer of Collected Personal Information

The Company provides personal information to the following overseas third parties and processes user personal information on servers located outside the country in which the user resides.

PlanetScale

ItemDetails
RecipientPlanetScale, Inc.
CountryUnited States (entity) / Japan (server location)
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://planetscale.com/legal/privacy
Data itemsMember information (nickname, email), booking and shoot records, payment records
PurposeHosting and operation of the service database
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Amazon Web Services

ItemDetails
RecipientAmazon Web Services, Inc.
CountryJapan
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://aws.amazon.com/compliance/contact
Data itemsPhotograph files
PurposeCloud storage of photograph files and server operation
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Cloudflare

ItemDetails
RecipientCloudflare, Inc.
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://www.cloudflare.com/privacypolicy/
Data itemsPhotograph files and public images
PurposeStorage and delivery of photograph files
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Vercel

ItemDetails
RecipientVercel Inc.
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://vercel.com/legal/privacy-policy
Data itemsAccess logs, service usage records, IP address
PurposeHosting of the service application
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Upstash

ItemDetails
RecipientUpstash, Inc.
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://upstash.com/trust/privacy.pdf
Data itemsCryptographic hash of the email address, authentication token identifier
PurposeLogin attempt throttling and blocking of revoked authentication tokens
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Stripe

ItemDetails
RecipientStripe, Inc.
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://stripe.com/privacy
Data itemsPayment information (payment method, transaction history), user identifiers (email, IP address, device information), billing information (name, contact)
PurposeProcessing and settlement of electronic payments
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Twilio (SendGrid)

ItemDetails
RecipientTwilio Inc.
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://www.twilio.com/en-us/legal/privacy
Data itemsEmail address, nickname
PurposeSending service notices and notification emails
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Google

ItemDetails
RecipientGoogle LLC
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://policies.google.com/privacy
Data itemsPush notification device token, social login account identifier, photographs submitted for AI retouching
PurposeSending app push notifications, social login authentication and AI photo retouching
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Apple

ItemDetails
RecipientApple Inc.
CountryUnited States
Timing and methodEncrypted transmission over the network at the time of service use
Privacy contacthttps://www.apple.com/legal/privacy/
Data itemsSocial login account identifier
PurposeSocial login authentication
RetentionUntil membership withdrawal or termination of the contract (or for the period required by other applicable laws)

Article 5. Procedures and Methods for Destruction of Personal Information

  1. The Company destroys personal information without delay when the personal information becomes unnecessary, such as when the retention period has elapsed or the purpose of processing has been achieved.
  2. If the retention period of personal information consented to by the data subject has elapsed or the purpose of processing has been achieved, but the personal information must be retained under other laws, such personal information shall be moved to a separate database (DB) or stored in a different location.
  3. The procedures and methods for the destruction of personal information are as follows.
  • Destruction procedure: The Company selects personal information for which a reason for destruction has occurred and destroys it with the approval of the personal information protection officer of Cheiz.
  • Destruction method: Personal information recorded and stored in electronic file form is destroyed in such a way that the records cannot be reproduced, and personal information recorded and stored on paper documents is shredded or incinerated.

Article 6. Rights and Obligations of Data Subjects and How to Exercise Them

As data subjects of personal information, users may exercise the following rights.

  1. The data subject may at any time exercise rights against Cheiz, including the right to access, correct, delete, or suspend the processing of personal information.
  2. The exercise of rights under paragraph 1 may be made to Cheiz in writing, by email, etc., pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company shall take action without delay.
  3. The exercise of rights under paragraph 1 may be made through an agent of the data subject. In this case, a power of attorney in the form of attached Form No. 11 of the Enforcement Rule of the Personal Information Protection Act must be submitted.
  4. Requests to access and suspend the processing of personal information may be limited under Articles 35(5) and 37(2) of the Personal Information Protection Act.
  5. Requests for correction and deletion of personal information cannot demand deletion if the personal information is specified as a collection target in other laws.
  6. When the Company receives a request for access, correction, deletion, or suspension of processing pursuant to the rights of the data subject, it confirms whether the requester is the data subject themselves or a legitimate agent.
  7. Members may access and modify their personal information by logging into the service and going to 'My Page > Settings'. However, the member ID (email) cannot be corrected.

Article 7. Measures to Ensure the Safety of Personal Information

Pursuant to Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative, and physical measures necessary to ensure safety.

  1. Administrative measures: Establishment and implementation of internal management plans, operation of dedicated organizations, regular employee training
  2. Technical measures: Management of access rights to personal information processing systems, etc.
  3. Physical measures: Access control to computer rooms, data storage rooms, etc.

Article 8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

  1. The Company uses 'cookies' that store and retrieve usage information from time to time in order to provide individualized customized services.
  2. Cookies are small pieces of information that the server (http) used to operate websites and mobile applications sends to users' computer browsers, and may be stored on the hard disks of users' PCs and mobile devices.

Purposes of using cookies:

  • Providing differentiated information according to individual interests
  • Analyzing members' access frequency or time spent to identify members' tastes and interests for use in target marketing
  • Tracking traces of contents browsed with interest to provide individualized customized services on the next access
  • Analyzing customers' habits for use as a measure for service reorganization, etc.

3. If you refuse to store cookies, you may experience difficulties in using customized services.

Article 9. Personal Information Protection Officer

1. The Company designates a personal information protection officer as follows to take overall responsibility for personal information processing operations and to handle complaints and damage relief related to personal information processing. (Contacting the contact information listed below will connect you to the head office.)

ItemDetails
NameDongjin Yang
DepartmentProduct Development / Service Operations
PositionCEO
Contact010-6617-6311 (Republic of Korea) / +81-78-600-9801 (Japan)
Emailteam@lifeshot.me

2. Data subjects may contact the personal information protection officer and the responsible department for any matters related to personal information protection inquiries, complaint handling, and damage relief that arise while using Cheiz's services (or business). The Company will respond to and handle the data subject's inquiries without delay.

Article 10. Remedies for Infringement of Data Subjects' Rights and Interests

1. Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency, the Personal Information Infringement Report Center, etc., in order to receive remedies for personal information infringement. For other reports and consultations regarding personal information infringement, please contact the following organizations.

OrganizationContactWebsite/Email
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
Personal Information Infringement Report Center118 (no area code)privacy.kisa.or.kr
Supreme Prosecutors’ Office1301 (no area code)www.spo.go.kr
National Police Agency182 (no area code)ecrm.cyber.go.kr

2. The Company guarantees the right of data subjects to self-determine their personal information and strives to provide consultation and damage relief for personal information infringement. If you need to file a report or consultation, please contact the following department.

ItemDetails
NameDongjin Yang
DepartmentDevelopment / Service Team
PositionCEO
Contact010-6617-6311 (Republic of Korea) / +81-78-600-9801 (Japan)
Emailteam@lifeshot.me

3. Any person whose rights or interests are infringed by a disposition or omission made by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal as prescribed by the Administrative Appeals Act.

OrganizationContactWebsite/Email
Central Administrative Appeals Commission110 (no area code)www.simpan.go.kr

Article 11. Changes to the Privacy Policy

  1. This Privacy Policy shall take effect from May 1, 2025.
  2. Previous versions of the Privacy Policy can be found below.

This Privacy Policy is effective from May 1, 2025.

Business Information

Korean Business Entity

ItemDetails
Business NameCheiz (치이즈)
Contact010-6617-6311
RepresentativeDongjin Yang
Business Registration No.820-41-00940
E-Commerce Registration No.2022-Incheon Yeonsu-1824
Address23F Open Office, 263 Central-ro, Yeonsu-gu, Incheon, Republic of Korea
Emailteam@lifeshot.me
"The Company" in this document株式会社LIFESHOT (LIFESHOT Inc.)

Japanese Corporation (Operating, Contracting and Payment Entity)

ItemDetails
CompanyLIFESHOT Inc. (株式会社LIFESHOT)
CEODongjin Yang
Address56 Naniwa-cho, Chuo-ku, Kobe City, Hyogo, 650-0035, Japan
Phone+81-78-600-9801 (Weekdays 10:00-18:00 JST)
Emailteam@lifeshot.me