THE Y
SEOUL
PRIVACY & DATA
Privacy Policy
Effective · July 19, 2026
0. Company & data protection officer
- Company: 주식회사 비즈코드 (Bizcode Co., Ltd.)
- Service: THE Y
- Co-CEOs: 최군성, 최재용
- Business registration no.: 560-81-03172
- Mail-order sales registration: 제 2026-인천미추홀-0705 호
- Address: 인천광역시 미추홀구 경인로325번길 27, 202동 301호(도화동, 주안역 미추홀 더리브)
- Email: official.yshorts@gmail.com
- Phone: 010-7175-3805
- Data Protection Officer: 최군성, 최재용
1. Purposes of processing
- We process personal data for sign-up, authentication, email verification, password reset, security and fraud prevention, unified login across our internal services, user-approved publishing to connected social channels, customer support, and compliance with legal obligations.
- If the purpose of processing changes, we obtain separate consent as required by applicable law.
2. Personal data we process
- Account data: email, name, password hash, email-verification status.
- Social sign-in data: provider (Google, KakaoTalk, or Naver), provider user identifier, email and name received from the provider, and last sign-in time. Sign-in provider access tokens are discarded immediately after profile retrieval and are not stored.
- Social-channel management data (only when the user connects that feature): platform, channel/account identifiers, display name and account type, permissions granted by the user, encrypted channel-management access and refresh tokens, user-approved publication, comment, message/inbox, and automation execution records, the limited content needed for an approved engagement feature, and uploaded-media metadata. Channel-management tokens are encrypted and kept only by THE Y; they are never provided to a connected THE-Y related service.
- Security data: login history, hashed session identifiers, hashed device identifiers, hashes of IP and browser information, two-factor challenge history.
- Operational data: terms-consent records, API client call logs, admin audit logs.
- THE Y does not store plaintext API client secrets, passwords, verification codes, or session tokens — they are stored as hashes.
- Payment data: connected service, order ID, selected provider (Toss or Paddle), provider transaction ID, return or cancellation URL, currency and FX snapshot, locale, and the minimum data needed to connect the result.
3. Retention & destruction
- Account data is retained until membership withdrawal or the expiry of a statutory retention period.
- Email-verification tokens and password-reset tokens are rendered unusable immediately upon fulfillment of their purpose or expiry.
- When a social channel is disconnected, THE-Y immediately blocks new channel activity, requests token revocation, and removes local credentials after its bounded revocation process. Provider-originated channel records and publication operations are removed with that connection; an original retained in the user's media library follows the separate media/account deletion choice. An account-deletion request includes that user's eligible uploaded media, channel data, publication operations, inbox data, and automation. Raw provider webhooks are retained for 7 days, unfinished uploads for 7 days after work ends, inbox body content for 90 days by default, and consent/audit records without body text for 1 year.
- Security logs are kept for the period necessary for incident response, failure analysis, and legal compliance, then destroyed or anonymized.
4. Third-party provision & entrustment of processing
- We do not sell personal data and do not share it for cross-context behavioral advertising.
- We may entrust processing only to the extent necessary to provide the service, such as email delivery, infrastructure operation, and database and cache operation.
- For any entrustment, we manage the processor, purpose, and retention period under applicable law and apply the necessary security measures.
- When a user chooses to connect or publish to an Instagram, Facebook, YouTube, TikTok, X, or Threads channel, that platform processes only the selected channel, post, comment or message, and minimum metadata needed for the approved platform feature under its own policy. THE Y repeats the provider-specific scope, limitation, and purpose immediately before connection.
- Cross-border processing: a selected platform may process the data required for its feature outside the user's country under its own policy. THE-Y does not enable a production connection until the provider-specific processing/transfer review and localized pre-connection notice have been approved; the current provider privacy-policy links are shown on the public Social support page and immediately before connection.
- Paddle.com Market Ltd. — merchant of record for Paddle-selected transactions, including payment, refunds, receipts, tax, and fraud prevention. Toss Payments — payment gateway for Toss-selected transactions, where BizCode Co., Ltd. remains the seller. THE Y does not directly collect or store card numbers.
5. Your rights
- You may request access to, correction of, deletion of, suspension of processing of, and withdrawal of consent for your personal data.
- Requests can be made through the in-service account management features or at official.yshorts@gmail.com.
- Dispute resolution (Korea): Personal Information Dispute Mediation Committee (1833-6972), Personal Information Infringement Report Center (118), Supreme Prosecutors' Office (1301), National Police Agency (182).
6. Cookies & sessions
- Essential cookies are used only for authentication sessions, admin sessions, and security.
- THE Y session cookies use the HttpOnly and SameSite attributes, and the Secure attribute in production.
7. Security & breach notification
- We apply transport encryption, Argon2id password hashing, key separation, access control, audit logging, account-abuse protections, and a no-plaintext-token policy.
- If a personal-data breach is confirmed or a potential breach is found, we notify affected users and the supervisory authority without delay as required by law.
- The notice includes the fact of the breach, the personal-data items affected, the time of the breach, measures to minimize harm, and remedies available.
8. Protection of minors
- THE Y is not directed at children.
- In Korea, those under 14 may not sign up without the consent of a legal representative; where this cannot be verified, use is restricted or data is destroyed without delay.
- We do not knowingly collect the personal data of U.S. children under 13. If a user is found to be under 13, the account is deleted and related data destroyed immediately.
- EU users under 16 (13–16 depending on the member state) require the consent of a parent or guardian.
9. Changes to this policy
- Material changes are announced at least 7 days before they take effect, and changes unfavorable to users at least 30 days before; where consent is required, separate consent is obtained.
10. Contact
- Address: 인천광역시 미추홀구 경인로325번길 27, 202동 301호(도화동, 주안역 미추홀 더리브)
- Phone: 010-7175-3805
- Email: official.yshorts@gmail.com
- Data Protection Officer: 최군성, 최재용
11. Google and YouTube API Services
- THE-Y uses YouTube API Services only for publishing and channel-management functions that the user connects and approves.
- YouTube features are subject to the YouTube Terms of Service (https://www.youtube.com/t/terms) and Google Privacy Policy (https://policies.google.com/privacy).
- You may revoke THE-Y's access to Google data at any time in Google Security Settings: https://security.google.com/settings/security/permissions.
- THE-Y processes only the approved channel data needed for the stated function. Access, storage, sharing, and deletion are described in this policy and in the channel-connection screen.