X30 X30
로그인

개인정보처리방침

Last updated: July 10, 2026 · Effective: July 10, 2026

X30 (hereinafter "Service") is operated by The Nines (hereinafter "Company"). In accordance with the Personal Information Protection Act and other applicable laws of the Republic of Korea, the Company has established and published this Privacy Policy to protect users' personal information and to handle related grievances promptly and efficiently.

1. Information We Collect

A. Categories of Information

Category Items
Required Email address, name, phone number, Instagram handle
Optional TikTok handle, YouTube channel, nationality, profile photo, bio
Automatically collected IP address, access logs (date/time, usage records), cookies, device information (browser type, OS)
Google OAuth Google account email, name, profile photo URL, Google unique identifier (UID)
Public social media metrics Instagram follower count, engagement rate, public post metrics (likes, comments, views, shares), post captions, and publicly available comments on submitted content
Internal economy data x30_reward_balances (CP balance and transaction history)
x30_trust_scores / x30_trust_logs (JEONG score and change records)
x30_referrals (invite_code, invited_at, profile_completed_at, reward_granted_at)

B. Methods of Collection

  • Information entered directly by users during registration and profile setup
  • Information entered directly by users during the Campaign application process
  • Information automatically collected through Google OAuth authentication
  • Information automatically generated and collected during use of the Service
  • Collection of publicly available Instagram and TikTok profile and post metrics via authorized third-party analytics services for campaign performance measurement

2. Purpose of Collection and Use

The Company uses the collected personal information for the following purposes:

  • Member management: Verification of registration intent, identity verification and authentication, maintenance and management of membership, prevention of fraudulent use
  • Campaign matching: Connecting influencers and business owners for Campaign applications, selection, and collaboration; notification of application results
  • Service improvement: Statistical analysis of service usage, development of new services, enhancement of service quality
  • Campaign performance analysis: Collection and analysis of publicly available social media metrics (follower count, engagement rate, post performance) to evaluate campaign outcomes and provide performance reports
  • Marketing (with consent): Notification of new Campaigns and event information (only where separate consent has been obtained)
  • Reward Points management: Accumulation, use, and expiration management of CP (Reward Points)
  • JEONG Trust Index: Calculation of JEONG Trust Index scores and improvement of Member matching quality
  • Referral tracking: Tracking of referral relationships and processing of referral rewards

3. Retention Period

In principle, the Company destroys personal information without delay once the purpose of collection and use has been fulfilled. However, the following information is retained for the periods specified:

Legal Basis Items Retained Retention Period
Act on Consumer Protection in Electronic Commerce Records of contracts or withdrawal of offers 5 years
Act on Consumer Protection in Electronic Commerce Records of payment and supply of goods/services 5 years
Act on Consumer Protection in Electronic Commerce Records of consumer complaints or dispute resolution 3 years
Protection of Communications Secrets Act Website access log records 3 months
Company internal policy Campaign-related content (content usage rights) 1 year after Campaign conclusion
  • Account deletion: A 7-day cooling-off period is provided after the deletion request, followed by approximately 6 months of retention in an inactive state for dispute resolution and fraud prevention. The information is not actively used during this period. Thereafter, account identity information (email address, phone number, name, Instagram handle, Google identifier, date of birth) is permanently destroyed. Items that must be retained under applicable law are isolated and retained separately: records of campaign visits that constitute transactions are kept in encrypted form for 5 years (Act on Consumer Protection in Electronic Commerce) and then destroyed. For applications that did not result in a visit, sensitive personal data is deleted when the account is destroyed, while non-identifying statistical data (e.g., campaign, status, dates) may be retained in anonymized form.
  • Marketing consent withdrawal: Information retained for marketing purposes is deleted immediately.

4. Third-Party Sharing

The Company does not, in principle, provide users' personal information to external parties. However, the following exceptions apply:

Recipient Items Shared Purpose Retention Period
Username/ID, display name, SNS handle, and a safe (virtual) contact number or in-app channel. For visit-type campaigns: the reserved visit date/time. For delivery-type campaigns: shipping address, recipient name, and a contact number for delivery. Applicant review, campaign communication, hosting of visits, and delivery of products (delivery campaigns) Up to 6 months after Campaign conclusion

Consent for such sharing is obtained at the time the user applies for a Campaign. Users have the right to refuse consent; however, refusal may restrict the ability to apply for Campaigns.

A Member's real email address and direct phone number are not provided to Business Owners, and free-text application notes are not shared; contact is mediated through a safe (virtual) relay number or an in-app channel. As an exception, for delivery-type campaigns where physical shipment requires it, the shipping address, recipient name, and a contact number are provided to the Business Owner (or its delivery agent) solely for the purpose of delivery.

CP Store redemptions: when a Member applies to redeem Reward Points (CP) for a product or service (e.g., a mobile gift voucher, restaurant voucher, or beauty/aesthetic service), the minimum information required for delivery or use (e.g., recipient name, contact number, and reservation details where applicable) is provided to the relevant product or service provider and delivery channel operator — such as gift-voucher delivery channels (e.g., Kakao Corp. for KakaoTalk Gift), restaurants, or beauty/aesthetic service providers — solely for the purpose of delivering or providing the redeemed item. By submitting a redemption request, the Member is deemed to consent to this provision, which occurs only when the Member applies.

A Business Owner that receives the information above acts as an independent data controller and is solely responsible for its retention, use, and destruction from the point of provision onward. The Company and the Business Owner are not joint controllers, as the Business Owner determines campaign operation and applicant selection independently.

Business owners: business owners who join the Service via invitation are managed under the Company's business-records retention policy; general inquiries submitted through the public contact form are processed by email only and are not stored in the Company's database.

In addition, personal information may be provided where required by law, or upon request from investigative authorities in accordance with the procedures and methods prescribed by applicable statutes.

The username (public handle) of a Referred Member who registered via a Referrer's invite code is made visible to that Referrer within the Service. By registering through an invite code, the Referred Member is deemed to have consented to this disclosure. Members who wish to opt out may submit a request to [email protected].

5. Outsourcing of Data Processing

The Company outsources the processing of personal information as follows to ensure smooth service delivery:

Service Provider Outsourced Tasks Server Location
DigitalOcean, LLC Server hosting and data storage Singapore
Resend, Inc. Transactional email delivery USA
Google LLC OAuth social login authentication; handling of inquiry and business email (Google Workspace) USA
Apify Technologies s.r.o. Collection of publicly available Instagram and TikTok profile and post metrics EU (Czech Republic)
Cloudflare, Inc. DNS, CDN, and web-traffic proxy for the Service (processing of access data such as IP addresses); storage and delivery of community images and other service media; database backup storage USA

Outsourcing contracts clearly stipulate compliance with personal information protection laws, confidentiality obligations, prohibition of third-party provision, and liability for damages in the event of a security incident.

Cross-border transfer: some of the service providers above are located outside the Republic of Korea (Singapore, the United States, the EU). For such international transfers, the Company relies on data processing agreements incorporating Standard Contractual Clauses (SCCs) or equivalent safeguards, and limits each transfer to what is necessary for the outsourced task.

Use of AI

  • Purpose: the Company uses AI tools (Anthropic, OpenAI) to develop, operate, support, and improve the Service. They are internal work tools acting only on the Company's instructions.
  • Minimization: data shared with them is limited to what is necessary and pseudonymized (identifiers, not raw email/phone/name) where feasible.
  • No training: your data is not used to train the providers' AI models or any model of the Company (per the providers' commercial/API terms).
  • Quality, safety & human review: providers may retain inputs for a limited period (typically up to ~30 days) for abuse monitoring, and authorized personnel (provider or Company) may review flagged content for safety and quality.
  • Recipients: data is shared only with these providers as processors for the purposes above — never sold or provided for their own independent use. They operate in the United States (covered by the SCCs above).
  • Personalized content (future): the Company may introduce AI-assisted personalized content or recommendations. There is no customer-facing AI feature today; if one is offered, the safeguards above apply and the Company will give notice and obtain consent or offer an opt-out as required.

6. Data Destruction

The Company destroys personal information without delay when it is no longer needed, such as upon expiration of the retention period or fulfillment of the purpose of processing.

A. Destruction Procedure

Information entered by users is transferred to a separate database (or separate documents in the case of paper records) after its purpose has been fulfilled, and is destroyed after a certain period in accordance with internal policies and applicable laws, or immediately.

B. Destruction Methods

  • Electronic files: Permanently deleted using technical methods that prevent the records from being reproduced.
  • Paper documents: Destroyed by shredding or incineration.

7. User Rights

Users (or their legal representatives) may exercise the following rights regarding their personal information at any time:

  • Request to access personal information
  • Request correction of inaccurate information
  • Request deletion of personal information
  • Request suspension of processing
  • Request to view CP (Reward Points) balance and transaction history, and submit disputes regarding CP
  • Request to view JEONG score change history, and submit disputes regarding score deductions
  • Request a portable copy of the personal information you provided, in a structured, commonly used format (data portability)

These rights may be exercised by emailing [email protected]. The Company will respond and take action without delay. Users in the European Union have additional rights, as described in the "Additional Rights for Users in the European Union" section below.

Rights may also be exercised through a legal representative or authorized agent. In such cases, a power of attorney in the form prescribed by the Enforcement Decree of the Personal Information Protection Act must be submitted.

The Company will verify whether the person making the request is the data subject or an authorized representative before processing any request for access, correction, deletion, or suspension of processing.

8. Cookies and Automatic Data Collection

A. Purpose of Cookies

The Company uses cookies to store and retrieve usage information in order to provide personalized services. Cookies are used to maintain login sessions and configure service settings. Cookies and access records are also used to compile visit statistics and analyze service usage for the purpose of improving the Service.

B. Cookie Management

Users have the option to accept or refuse cookies. By adjusting browser settings, users may accept all cookies, require confirmation before each cookie is stored, or refuse all cookies.

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Safari: Preferences → Privacy → Manage website data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data

Please note that refusing cookies may cause difficulty in using certain features of the Service that require login.

C. Third-Party Tags and Behavioral Advertising

The Service uses Google Tag Manager and Google Ads conversion tracking (Google LLC, USA). These tools may collect behavioral information — such as cookies, advertising identifiers, and page-visit records — to measure advertising conversions (e.g., business inquiry submissions) and improve advertising campaigns. This information does not directly identify you by name, and the Company does not provide your account or profile data to Google through these tags. Retention follows Google's policies. You may opt out at any time via Google Ads Settings or by blocking cookies as described above. For visitors in the EU/EEA, the United Kingdom, and Switzerland, advertising signals are set to denied by default until you consent through the cookie banner (Google Consent Mode v2).

Fonts and scripts: web fonts and JavaScript libraries are served directly from the Company's own servers (self-hosted). Loading them does not send any personal information — including your IP address — to an external font or script CDN.

9. Protection of Minors

  1. Registration is available only to individuals aged 17 or older. The Company does not accept registration from anyone under the age of 17. If the Company discovers that personal information of a user under 17 has been collected at registration, it will be deleted immediately and will not be used for any purpose. (Members aged 14 to 16 who registered under the previous policy retain their accounts; the change does not apply retroactively.)
  2. Because Korean civil law treats individuals under the age of 19 as minors, Members aged 17 or 18 must obtain verified consent from a parent or legal guardian (via email) before applying for any Campaign.

9-2. Data Encryption

The Company encrypts sensitive personal data, including email addresses, phone numbers, and dates of birth, at rest using ActiveRecord::Encryption. All data in transit is protected via SSL/TLS encryption.

10. Chief Privacy Officer (CPO) and Grievance Handling

The Company has designated the following Chief Privacy Officer to oversee the processing of personal information and to handle user complaints and remedies related to personal information:

Chief Privacy Officer (CPO)

Title: X30 Operations Team Manager

Email: [email protected]

Users may contact the CPO regarding any inquiries, complaints, or remedies related to personal information protection arising from the use of the Service. The Company will respond and take action without delay.

For additional reporting or consultation regarding personal information infringement, please contact the following organizations:

  • Personal Information Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr / 118
  • Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
  • Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301
  • National Police Agency Cyber Bureau: ecrm.cyber.go.kr / 182

Users in the European Union may also lodge a complaint with their local data protection supervisory authority — see the "Additional Rights for Users in the European Union" section below.

11. Additional Rights for Users in the European Union

Where the EU General Data Protection Regulation (GDPR) applies to a user (e.g., users in the European Union/EEA), the following additional terms apply, in addition to the rights described above.

A. Legal Bases for Processing (Art. 6)

  • Performance of a contract: member management, campaign matching, and provision of the Service.
  • Legal obligation: retention of transaction and other records required by applicable statutes.
  • Legitimate interests: prevention of fraudulent use, service improvement and statistics (using pseudonymized/aggregated data), and providing the minimum pseudonymous information necessary for Business Owners to host campaign visits. The Company maintains a documented Legitimate Interest Assessment for these activities.
  • Consent: marketing communications and the sharing of information with Business Owners at the time of Campaign application. Consent may be withdrawn at any time.

B. International Transfers (Art. 44–50)

Personal information may be transferred to and processed in countries outside the EEA (the Republic of Korea, Singapore, and the United States). Such transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards, and are limited to what is necessary for the stated purpose.

C. Automated Decision-Making and Profiling (Art. 22)

The Service uses automated processing, including the JEONG Trust Index, campaign ranking, and eligibility filtering, which may involve profiling. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you. You may request human review of such a decision, express your point of view, and contest the decision by emailing [email protected].

D. Your GDPR Rights and Erasure

You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (Arts. 15–22). Regarding erasure: where records are subject to statutory retention under Korean law, and that retention does not by itself fall within Art. 17(3)(b), the Company retains such records on the basis of the establishment, exercise, or defence of legal claims (Art. 17(3)(e)) together with its documented Legitimate Interest Assessment. Erasure requests are reviewed on a case-by-case basis, and where retention is upheld, the Company restricts processing of the retained record to the defence of legal claims only (Art. 18) — ceasing any marketing, analytics, or profiling use and deleting data not necessary for that purpose — and informs you of the reason, the retention period, and the destruction date.

E. Right to Lodge a Complaint (Art. 77)

You have the right to lodge a complaint with the data protection supervisory authority of your EU/EEA member state. A list of national authorities is published by the European Data Protection Board (edpb.europa.eu).

F. EU Representative (Art. 27)

Given the Company's limited and occasional processing of EU residents' data at present, an EU representative has not been appointed. The Company will appoint a representative if and when required by the scale of its processing, and will update this Policy accordingly.

Appendix. Marketing Consent Wording (by Version)

The exact opt-in wording presented when the Company collects marketing consent is preserved below so that you can verify what you agreed to under each policy version. Each consent and withdrawal event is recorded together with the policy version in force at the time, and consent may be withdrawn at any time in Profile settings.

  • Sign-up (onboarding): "Send me updates about new campaigns and opportunities." (Optional) / 국문: "마케팅 이메일 및 알림 수신에 동의합니다. (선택)"
  • Campaign application form: "I agree to receive campaign-related marketing information." / 국문: "캠페인 관련 마케팅 정보 수신에 동의합니다 (선택)"
  • Profile settings: "Marketing Consent — Receive event, promotion, and new campaign notifications" / 국문: "마케팅 정보 수신 동의 — 이벤트, 프로모션, 새 캠페인 알림을 받습니다"

This wording has remained unchanged across policy versions 2026-03-17, 2026-05-24, and 2026-07-10. (One correction: prior to March 17, 2026 the Korean application-form label was mislabelled "[필수]" (required); it was corrected to "(선택)" (optional) on March 17, 2026.)

Revision Notice

This revision (data-retention policy update, EU/GDPR additions, raising of the minimum registration age to 17, advertiser-controller clarification, and AI/cross-border-transfer disclosures, addition of Community board and CP Store provisions) is a material change. In accordance with the Company's notice procedure, it takes effect after at least 30 days' advance notice to Members. Effective date: July 10, 2026 for existing members (following the June 10, 2026 advance notice); new registrations are covered from the date of publication.

Supplemented on July 10, 2026 (publication date): disclosures were expanded for processing already in operation — TikTok public-metrics collection, Google tags (Tag Manager / Ads conversion tracking), inquiry email handling via Google Workspace, Cloudflare traffic proxy and database backup storage, font CDNs, and the marketing consent wording appendix. No new categories of personal information are collected by this supplement.

Revision History

  • July 10, 2026 (current) — Data-retention update, EU/GDPR additions, minimum age 17, advertiser independent-controller clarification, AI and cross-border-transfer disclosures, Community board and CP Store provisions; processor and behavioral-advertising disclosures supplemented on publication.
  • May 24, 2026 — Reward Points (CP) / JEONG / Invite processing reflected (revised April 24, 2026). View archived version
  • March 17, 2026 — Initial Privacy Policy. View archived version