This Privacy Policy applies to the BeMoon service and website (https://bemoon.co.kr).
BeMoon ("Company") values users' personal information and complies with applicable laws and regulations, including the Personal Information Protection Act. This Privacy Policy explains what personal information we collect, how we use and protect it, and what rights users have regarding their personal information.
1. Personal Information Collected
The Company may collect the following personal information to provide its services.
During Registration, Login, and Google OAuth Authentication
Required Items: Email address (Google account), name, and profile image
The Company does not directly collect or store users' passwords.
The Company may receive users' email addresses, names, and profile images through Google OAuth authentication. This information is used solely for login and account identification purposes.
Profile Information
Information voluntarily provided by users: Name, year of birth, school name, grade level, and any other information voluntarily entered by users
Information Automatically Collected During Service Use
IP address, cookies, access date and time, browser information, operating system information, device information, service usage records, problem-solving records, accuracy rates and learning statistics, and records of abnormal or fraudulent usage
During Use of Paid Services
Payment history, subscription status, purchase records, transaction identifiers, and refund records
The Company uses external payment service providers such as Paddle and does not directly store sensitive financial information, including users' full credit card numbers.
Customer Support and Surveys
Email address, inquiry content, attached files, and other information voluntarily provided by users
2. Purpose of Processing Personal Information
The Company uses collected personal information only for the following purposes.
Member Management: User identification, Login authentication, Account management, Membership withdrawal processing, Prevention of unauthorized or fraudulent use
Service Improvement: Improving service quality, Developing new features, Analyzing and fixing errors, Analyzing usage statistics
Customer Support: Receiving and responding to inquiries, Delivering announcements, Providing service-related information
3. Provision of Personal Information to Third Parties
The Company does not provide users' personal information to third parties except in the following cases.
When users have provided prior consent
When required by applicable laws and regulations
When requested by law enforcement or governmental authorities in accordance with applicable laws
4. Entrustment of Personal Information Processing and International Data Transfer
The Company uses the following service providers to operate its services. Personal information may be processed and stored on servers located outside of Korea.
Supabase (United States): User authentication and data storage (email address, profile information, learning records, subscription status, payment records)
Paddle (United Kingdom): Payment processing, subscription management, refund processing, and transaction record management
5. Retention Period of Personal Information
The Company will destroy personal information without delay once the purpose of collection and use has been fulfilled, unless retention is required by applicable laws.
Consumer Complaints and Dispute Resolution Records: Retention Period, 3 years
Records Related to Contracts or Withdrawal of Subscription: Retention Period, 5 years
Records Related to Payments and Service Provision: Retention Period, 5 years
6. Destruction of Personal Information
Personal information is destroyed immediately upon expiration of the retention period or achievement of the processing purpose.
Electronic files containing personal information are permanently deleted using methods that prevent recovery.
Printed documents containing personal information are destroyed by shredding, incineration, or equivalent methods.
7. Users' Rights and How to Exercise Them
Users may at any time exercise their rights to access, correct, or delete their personal information, request suspension of processing, or withdraw their membership.
Upon account deletion, personal information will be deleted immediately unless retention is required by applicable laws.
Usage Analytics: Google Analytics, Vercel Analytics
Service Quality Improvement: Error analysis, Performance measurement
9. Measures to Protect Personal Information
The Company implements the following measures to protect personal information.
HTTPS encrypted communications, OAuth-based authentication systems, Principle of least privilege access control, Use of secure cloud infrastructure, Regular security reviews and monitoring
10. Chief Privacy Officer
The Company designates the following individual as responsible for personal information protection and related inquiries.