X30 X30
Sign In

Privacy Policy

Last updated: August 11, 2026 · Effective: August 11, 2026

X30 (hereinafter "Service") is operated by The Nines (hereinafter "Company"). In accordance with the Personal Information Protection Act and other applicable laws of the Republic of Korea, the Company has established and published this Privacy Policy to protect users' personal information and to handle related grievances promptly and efficiently.

1. Information We Collect

A. Categories of Information

Category Items
Required Email address, name, phone number, Instagram handle
Optional TikTok handle, YouTube channel, nationality, profile photo, bio
Automatically collected IP address, access logs (date/time, usage records), cookies, device information (browser type, OS)
Google OAuth Google account email, name, profile photo URL, Google unique identifier (UID)
Public social media metrics Instagram follower count, engagement rate, public post metrics (likes, comments, views, shares), post captions, and publicly available comments on submitted content
Internal economy data x30_reward_balances (CP balance and transaction history)
x30_trust_scores / x30_trust_logs (JEONG score and change records)
x30_referrals (invite_code, invited_at, profile_completed_at, reward_granted_at)
Email open records Whether an email sent by the Company was opened and the time it was opened, together with the IP address and mail client (email app, browser, operating system) recorded by the email service provider at the moment of opening. Collected only for bulk announcement and newsletter emails the Company sends to Members; the recipients of any given send may be all Members or a specific group of them. Not collected for one-to-one emails sent in the course of using the Service, such as login codes, application results, or campaign notifications.

B. Methods of Collection

  • Information entered directly by users during registration and profile setup
  • Information entered directly by users during the Campaign application process
  • Information automatically collected through Google OAuth authentication
  • Information automatically generated and collected during use of the Service
  • Collection of publicly available Instagram and TikTok profile and post metrics via authorized third-party analytics services for campaign performance measurement
  • Automatic collection through a 1x1 transparent image embedded in bulk announcement and newsletter emails, which records that the email was opened (see Section 8-D)

2. Purpose of Collection and Use

The Company uses the collected personal information for the following purposes:

  • Member management: Verification of registration intent, identity verification and authentication, maintenance and management of membership, prevention of fraudulent use
  • Campaign matching: Connecting influencers and business owners for Campaign applications, selection, and collaboration; notification of application results
  • Service improvement: Statistical analysis of service usage, development of new services, enhancement of service quality
  • Campaign performance analysis: Collection and analysis of publicly available social media metrics (follower count, engagement rate, post performance) to evaluate campaign outcomes and provide performance reports
  • Marketing (with consent): Notification of new Campaigns and event information (only where separate consent has been obtained)
  • Email open measurement: Measuring whether bulk announcement and newsletter emails are opened, in order to evaluate how well the Company's communications reach Members, decide how often and what to send, and improve the Service
  • Reward Points management: Accumulation, use, and expiration management of CP (Reward Points)
  • JEONG Trust Index: Calculation of JEONG Trust Index scores and improvement of Member matching quality
  • Referral tracking: Tracking of referral relationships and processing of referral rewards

3. Retention Period

In principle, the Company destroys personal information without delay once the purpose of collection and use has been fulfilled. However, the following information is retained for the periods specified:

Legal Basis Items Retained Retention Period
Act on Consumer Protection in Electronic Commerce Records of contracts or withdrawal of offers 5 years
Act on Consumer Protection in Electronic Commerce Records of payment and supply of goods/services 5 years
Act on Consumer Protection in Electronic Commerce Records of consumer complaints or dispute resolution 3 years
Protection of Communications Secrets Act Website access log records 3 months
Company internal policy Campaign-related content (content usage rights) 1 year after Campaign conclusion
Company internal policy Email open records (open status, open time, and the IP address and mail client recorded on opening) Not stored on the Company's own servers; retained by the email service provider for approximately 30 days from the send date and then deleted
  • Account deletion: A 7-day cooling-off period is provided after the deletion request, followed by approximately 6 months of retention in an inactive state for dispute resolution and fraud prevention. The information is not actively used during this period. Thereafter, account identity information (email address, phone number, name, Instagram handle, Google identifier, date of birth) is permanently destroyed. Items that must be retained under applicable law are isolated and retained separately: records of campaign visits that constitute transactions are kept in encrypted form for 5 years (Act on Consumer Protection in Electronic Commerce) and then destroyed. For applications that did not result in a visit, sensitive personal data is deleted when the account is destroyed, while non-identifying statistical data (e.g., campaign, status, dates) may be retained in anonymized form.
  • Marketing consent withdrawal: Information retained for marketing purposes is deleted immediately.

4. Third-Party Sharing

The Company does not, in principle, provide users' personal information to external parties. However, the following exceptions apply:

Recipient Items Shared Purpose Retention Period
Username/ID, display name, SNS handle, and a safe (virtual) contact number or in-app channel. For visit-type campaigns: the reserved visit date/time. For delivery-type campaigns: shipping address, recipient name, and a contact number for delivery. Applicant review, campaign communication, hosting of visits, and delivery of products (delivery campaigns) Up to 6 months after Campaign conclusion

Consent for such sharing is obtained at the time the user applies for a Campaign. Users have the right to refuse consent; however, refusal may restrict the ability to apply for Campaigns.

A Member's real email address and direct phone number are not provided to Business Owners, and free-text application notes are not shared; contact is mediated through a safe (virtual) relay number or an in-app channel. As an exception, for delivery-type campaigns where physical shipment requires it, the shipping address, recipient name, and a contact number are provided to the Business Owner (or its delivery agent) solely for the purpose of delivery.

CP Store redemptions: when a Member applies to redeem Reward Points (CP) for a product or service (e.g., a mobile gift voucher, restaurant voucher, beauty/aesthetic service, or a physical product), the minimum information required for delivery or use (e.g., recipient name, contact number, and — for physical products, a shipping address including postcode — or reservation details where applicable) is provided to the relevant product or service provider and delivery channel operator — such as gift-voucher delivery channels (e.g., Kakao Corp. for KakaoTalk Gift), restaurants, beauty/aesthetic service providers, or shipping carriers — solely for the purpose of delivering or providing the redeemed item. Physical-product redemptions are limited to shipping addresses within Korea. By submitting a redemption request, the Member is deemed to consent to this provision, which occurs only when the Member applies. This delivery information is used solely for that purpose and is deleted immediately once the item has been sent or the redemption request has been declined.

A Business Owner that receives the information above acts as an independent data controller and is solely responsible for its retention, use, and destruction from the point of provision onward. The Company and the Business Owner are not joint controllers, as the Business Owner determines campaign operation and applicant selection independently.

Business owners: business owners who join the Service via invitation are managed under the Company's business-records retention policy; general inquiries submitted through the public contact form are processed by email only and are not stored in the Company's database.

In addition, personal information may be provided where required by law, or upon request from investigative authorities in accordance with the procedures and methods prescribed by applicable statutes.

The username (public handle) of a Referred Member who registered via a Referrer's invite code is made visible to that Referrer within the Service. By registering through an invite code, the Referred Member is deemed to have consented to this disclosure. Members who wish to opt out may submit a request to [email protected].

5. Outsourcing of Data Processing

The Company outsources the processing of personal information as follows to ensure smooth service delivery:

Service Provider Outsourced Tasks Server Location
DigitalOcean, LLC Server hosting and data storage Singapore
Resend, Inc. Email delivery (one-to-one service emails as well as bulk announcement and newsletter emails) and measurement of email opens for bulk announcement and newsletter emails (open status and time, together with the IP address and mail client recorded on opening) USA
Google LLC OAuth social login authentication; handling of inquiry and business email (Google Workspace) USA
Apify Technologies s.r.o. Collection of publicly available Instagram and TikTok profile and post metrics EU (Czech Republic)
Cloudflare, Inc. DNS, CDN, and web-traffic proxy for the Service (processing of access data such as IP addresses); storage and delivery of community images and other service media; database backup storage USA

Outsourcing contracts clearly stipulate compliance with personal information protection laws, confidentiality obligations, prohibition of third-party provision, and liability for damages in the event of a security incident.

Cross-border transfer: some of the service providers above are located outside the Republic of Korea (Singapore, the United States, the EU). For such international transfers, the Company relies on data processing agreements incorporating Standard Contractual Clauses (SCCs) or equivalent safeguards, and limits each transfer to what is necessary for the outsourced task.

Use of AI

  • Purpose: the Company uses AI tools (Anthropic, OpenAI) to develop, operate, support, and improve the Service. They are internal work tools acting only on the Company's instructions.
  • Minimization: data shared with them is limited to what is necessary and pseudonymized (identifiers, not raw email/phone/name) where feasible.
  • No training: your data is not used to train the providers' AI models or any model of the Company (per the providers' commercial/API terms).
  • Quality, safety & human review: providers may retain inputs for a limited period (typically up to ~30 days) for abuse monitoring, and authorized personnel (provider or Company) may review flagged content for safety and quality.
  • Recipients: data is shared only with these providers as processors for the purposes above — never sold or provided for their own independent use. They operate in the United States (covered by the SCCs above).
  • Personalized content (future): the Company may introduce AI-assisted personalized content or recommendations. There is no customer-facing AI feature today; if one is offered, the safeguards above apply and the Company will give notice and obtain consent or offer an opt-out as required.

6. Data Destruction

The Company destroys personal information without delay when it is no longer needed, such as upon expiration of the retention period or fulfillment of the purpose of processing.

A. Destruction Procedure

Information entered by users is transferred to a separate database (or separate documents in the case of paper records) after its purpose has been fulfilled, and is destroyed after a certain period in accordance with internal policies and applicable laws, or immediately.

B. Destruction Methods

  • Electronic files: Permanently deleted using technical methods that prevent the records from being reproduced.
  • Paper documents: Destroyed by shredding or incineration.

7. User Rights

Users (or their legal representatives) may exercise the following rights regarding their personal information at any time:

  • Request to access personal information
  • Request correction of inaccurate information
  • Request deletion of personal information
  • Request suspension of processing
  • Request to view CP (Reward Points) balance and transaction history, and submit disputes regarding CP
  • Request to view JEONG score change history, and submit disputes regarding score deductions
  • Request a portable copy of the personal information you provided, in a structured, commonly used format (data portability)

These rights may be exercised by emailing [email protected]. The Company will respond and take action without delay. Users in the European Union have additional rights, as described in the "Additional Rights for Users in the European Union" section below.

Rights may also be exercised through a legal representative or authorized agent. In such cases, a power of attorney in the form prescribed by the Enforcement Decree of the Personal Information Protection Act must be submitted.

The Company will verify whether the person making the request is the data subject or an authorized representative before processing any request for access, correction, deletion, or suspension of processing.

8. Cookies and Automatic Data Collection

A. Purpose of Cookies

The Company uses cookies to store and retrieve usage information in order to provide personalized services. Cookies are used to maintain login sessions and configure service settings. Cookies and access records are also used to compile visit statistics and analyze service usage for the purpose of improving the Service.

B. Cookie Management

Users have the option to accept or refuse cookies. By adjusting browser settings, users may accept all cookies, require confirmation before each cookie is stored, or refuse all cookies.

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Safari: Preferences → Privacy → Manage website data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data

Please note that refusing cookies may cause difficulty in using certain features of the Service that require login.

C. Third-Party Tags and Behavioral Advertising

The Service uses Google Tag Manager and Google Ads conversion tracking (Google LLC, USA). These tools may collect behavioral information — such as cookies, advertising identifiers, and page-visit records — to measure advertising conversions (e.g., business inquiry submissions) and improve advertising campaigns. This information does not directly identify you by name, and the Company does not provide your account or profile data to Google through these tags. Retention follows Google's policies. You may opt out at any time via Google Ads Settings or by blocking cookies as described above. For visitors in the EU/EEA, the United Kingdom, and Switzerland, advertising signals are set to denied by default until you consent through the cookie banner (Google Consent Mode v2).

Fonts and scripts: web fonts and JavaScript libraries are served directly from the Company's own servers (self-hosted). Loading them does not send any personal information — including your IP address — to an external font or script CDN.

D. Email Open Measurement

Bulk announcement and newsletter emails the Company sends to Members contain a 1x1 transparent image (a "tracking pixel"). The recipients of a given send may be all Members or a specific group of them — for example, only Members who have given marketing consent. When your mail client downloads that image, the email service provider records that the message was opened, the time it was opened, and the IP address and mail client used. The record is held by that provider; the Company does not store it on its own servers and reads it as a per-send total (how many recipients opened a given email). One-to-one emails sent in the course of using the Service — login codes, application results, campaign notifications, and similar notices — do not contain the pixel.

Open figures are approximate and tend to overstate actual reading. Apple Mail Privacy Protection and the Gmail image proxy download images on your behalf without you opening the message, which is counted as an open; conversely, an email you did read is not counted if images never load.

You can prevent this collection by turning off automatic image loading in your mail client (for example, Gmail: Settings → General → Images → "Ask before displaying external images"; Apple Mail: Settings → Privacy → turn off "Protect Mail Activity" and "Load remote content"). If images are not loaded, no open record is created. You may also stop receiving marketing emails entirely by withdrawing marketing consent in Profile settings or using the unsubscribe link in the email.

9. Protection of Minors

  1. Registration is available only to individuals aged 17 or older. The Company does not accept registration from anyone under the age of 17. If the Company discovers that personal information of a user under 17 has been collected at registration, it will be deleted immediately and will not be used for any purpose. (Members aged 14 to 16 who registered under the previous policy retain their accounts; the change does not apply retroactively.)
  2. Because Korean civil law treats individuals under the age of 19 as minors, Members aged 17 or 18 must obtain verified consent from a parent or legal guardian (via email) before applying for any Campaign.

9-2. Data Encryption

The Company encrypts sensitive personal data, including email addresses, phone numbers, and dates of birth, at rest using ActiveRecord::Encryption. All data in transit is protected via SSL/TLS encryption.

10. Chief Privacy Officer (CPO) and Grievance Handling

The Company has designated the following Chief Privacy Officer to oversee the processing of personal information and to handle user complaints and remedies related to personal information:

Chief Privacy Officer (CPO)

Title: X30 Operations Team Manager

Email: [email protected]

Users may contact the CPO regarding any inquiries, complaints, or remedies related to personal information protection arising from the use of the Service. The Company will respond and take action without delay.

For additional reporting or consultation regarding personal information infringement, please contact the following organizations:

  • Personal Information Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr / 118
  • Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
  • Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301
  • National Police Agency Cyber Bureau: ecrm.cyber.go.kr / 182

Users in the European Union may also lodge a complaint with their local data protection supervisory authority — see the "Additional Rights for Users in the European Union" section below.

11. Additional Rights for Users in the European Union

Where the EU General Data Protection Regulation (GDPR) applies to a user (e.g., users in the European Union/EEA), the following additional terms apply, in addition to the rights described above.

A. Legal Bases for Processing (Art. 6)

  • Performance of a contract: member management, campaign matching, and provision of the Service.
  • Legal obligation: retention of transaction and other records required by applicable statutes.
  • Legitimate interests: prevention of fraudulent use, service improvement and statistics (using pseudonymized/aggregated data), and providing the minimum pseudonymous information necessary for Business Owners to host campaign visits. The Company maintains a documented Legitimate Interest Assessment for these activities.
  • Consent: marketing communications and the sharing of information with Business Owners at the time of Campaign application. Consent may be withdrawn at any time.

B. International Transfers (Art. 44–50)

Personal information may be transferred to and processed in countries outside the EEA (the Republic of Korea, Singapore, and the United States). Such transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards, and are limited to what is necessary for the stated purpose.

C. Automated Decision-Making and Profiling (Art. 22)

The Service uses automated processing, including the JEONG Trust Index, campaign ranking, and eligibility filtering, which may involve profiling. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you. You may request human review of such a decision, express your point of view, and contest the decision by emailing [email protected].

D. Your GDPR Rights and Erasure

You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (Arts. 15–22). Regarding erasure: where records are subject to statutory retention under Korean law, and that retention does not by itself fall within Art. 17(3)(b), the Company retains such records on the basis of the establishment, exercise, or defence of legal claims (Art. 17(3)(e)) together with its documented Legitimate Interest Assessment. Erasure requests are reviewed on a case-by-case basis, and where retention is upheld, the Company restricts processing of the retained record to the defence of legal claims only (Art. 18) — ceasing any marketing, analytics, or profiling use and deleting data not necessary for that purpose — and informs you of the reason, the retention period, and the destruction date.

E. Right to Lodge a Complaint (Art. 77)

You have the right to lodge a complaint with the data protection supervisory authority of your EU/EEA member state. A list of national authorities is published by the European Data Protection Board (edpb.europa.eu).

F. EU Representative (Art. 27)

Given the Company's limited and occasional processing of EU residents' data at present, an EU representative has not been appointed. The Company will appoint a representative if and when required by the scale of its processing, and will update this Policy accordingly.

Appendix. Marketing Consent Wording (by Version)

The exact opt-in wording presented when the Company collects marketing consent is preserved below so that you can verify what you agreed to under each policy version. Each consent and withdrawal event is recorded together with a policy version string. That version string is raised only for revisions that ask Members to consent again; a revision that changes wording alone — such as the August 11, 2026 revision — keeps the previous version string, and the record instead carries a separate wording tag. A record with no wording tag reflects the wording in force before August 11, 2026; a record tagged "2026-08-11-open-tracking" reflects the wording in force from that date. Consent may be withdrawn at any time in Profile settings.

  • Sign-up (onboarding): "Send me updates about new campaigns and opportunities." (Optional) / 국문: "마케팅 이메일 및 알림 수신에 동의합니다. (선택)"
  • Campaign application form: "I agree to receive campaign-related marketing information." / 국문: "캠페인 관련 마케팅 정보 수신에 동의합니다 (선택)"
  • Profile settings: "Marketing Consent — Receive event, promotion, and new campaign notifications" / 국문: "마케팅 정보 수신 동의 — 이벤트, 프로모션, 새 캠페인 알림을 받습니다"

This wording has remained unchanged across policy versions 2026-03-17, 2026-05-24, and 2026-07-10. (One correction: prior to March 17, 2026 the Korean application-form label was mislabelled "[필수]" (required); it was corrected to "(선택)" (optional) on March 17, 2026.)

Revision Notice

August 11, 2026 revision: bulk announcement and newsletter emails the Company sends to Members now carry a 1x1 transparent image that records whether the email was opened and when. Sections 1, 2, 3, 5, and 8 have been updated accordingly, and the required privacy consent presented at sign-up now states this. Announcement emails go to Members regardless of marketing consent, so this is not limited to Members who opted in to marketing. Nothing changes in how the Service itself, campaign participation, or rewards work, and one-to-one transactional emails are not measured. This revision takes effect on its publication date, August 11, 2026. If you would rather not have opens recorded, turn off automatic image loading in your mail client (Section 8-D); to stop receiving marketing emails altogether, withdraw marketing consent in Profile settings.

The July 10, 2026 revision (data-retention policy update, EU/GDPR additions, raising of the minimum registration age to 17, advertiser-controller clarification, and AI/cross-border-transfer disclosures, addition of Community board and CP Store provisions) is a material change. In accordance with the Company's notice procedure, it takes effect after at least 30 days' advance notice to Members. Effective date: July 10, 2026 for existing members (following the June 10, 2026 advance notice); new registrations are covered from the date of publication.

Supplemented on July 10, 2026 (publication date): disclosures were expanded for processing already in operation — TikTok public-metrics collection, Google tags (Tag Manager / Ads conversion tracking), inquiry email handling via Google Workspace, Cloudflare traffic proxy and database backup storage, font CDNs, and the marketing consent wording appendix. No new categories of personal information are collected by this supplement.

Revision History

  • August 11, 2026 (current) — Email open measurement for bulk announcement and newsletter emails (collection items, purpose, retention period, Resend outsourcing scope, and the automatic-collection section), and updated sign-up privacy consent wording.
  • July 10, 2026 — Data-retention update, EU/GDPR additions, minimum age 17, advertiser independent-controller clarification, AI and cross-border-transfer disclosures, Community board and CP Store provisions; processor and behavioral-advertising disclosures supplemented on publication. View archived version
  • May 24, 2026 — Reward Points (CP) / JEONG / Invite processing reflected (revised April 24, 2026). View archived version
  • March 17, 2026 — Initial Privacy Policy. View archived version