Privacy Policy

Last updated: March 17, 2026

X30 (hereinafter "Service") is operated by The Nines (hereinafter "Company"). In accordance with the Personal Information Protection Act and other applicable laws of the Republic of Korea, the Company has established and published this Privacy Policy to protect users' personal information and to handle related grievances promptly and efficiently.

1. Information We Collect

A. Categories of Information

Category Items
Required Email address, name, phone number, Instagram handle
Optional TikTok handle, YouTube channel, nationality, profile photo, bio
Automatically collected IP address, access logs (date/time, usage records), cookies, device information (browser type, OS)
Google OAuth Google account email, name, profile photo URL, Google unique identifier (UID)
Public social media metrics Instagram follower count, engagement rate, public post metrics (likes, comments, views, shares), post captions, and publicly available comments on submitted content

B. Methods of Collection

  • Information entered directly by users during registration and profile setup
  • Information entered directly by users during the Campaign application process
  • Information automatically collected through Google OAuth authentication
  • Information automatically generated and collected during use of the Service
  • Collection of publicly available Instagram profile and post metrics via authorized third-party analytics services for campaign performance measurement

2. Purpose of Collection and Use

The Company uses the collected personal information for the following purposes:

  • Member management: Verification of registration intent, identity verification and authentication, maintenance and management of membership, prevention of fraudulent use
  • Campaign matching: Connecting influencers and business owners for Campaign applications, selection, and collaboration; notification of application results
  • Service improvement: Statistical analysis of service usage, development of new services, enhancement of service quality
  • Campaign performance analysis: Collection and analysis of publicly available social media metrics (follower count, engagement rate, post performance) to evaluate campaign outcomes and provide performance reports
  • Marketing (with consent): Notification of new Campaigns and event information (only where separate consent has been obtained)

3. Retention Period

In principle, the Company destroys personal information without delay once the purpose of collection and use has been fulfilled. However, the following information is retained for the periods specified:

Legal Basis Items Retained Retention Period
Act on Consumer Protection in Electronic Commerce Records of contracts or withdrawal of offers 5 years
Act on Consumer Protection in Electronic Commerce Records of payment and supply of goods/services 5 years
Act on Consumer Protection in Electronic Commerce Records of consumer complaints or dispute resolution 3 years
Protection of Communications Secrets Act Website access log records 3 months
Company internal policy Campaign-related content (content usage rights) 1 year after Campaign conclusion
  • Account deletion: A 7-day cooling-off period is provided after the deletion request, followed by a 6-month retention period in inactive status for dispute resolution and fraud prevention purposes. The information is not actively used during retention and is destroyed after the 6-month period, excluding items required to be retained by law.
  • Marketing consent withdrawal: Information retained for marketing purposes is deleted immediately.

4. Third-Party Sharing

The Company does not, in principle, provide users' personal information to external parties. However, the following exceptions apply:

Recipient Items Shared Purpose Retention Period
Campaign Business Owner Name, email, Instagram handle, phone number, application notes Review of Campaign applicants and collaboration Up to 6 months after Campaign conclusion

Consent for such sharing is obtained at the time the user applies for a Campaign. Users have the right to refuse consent; however, refusal may restrict the ability to apply for Campaigns.

In addition, personal information may be provided where required by law, or upon request from investigative authorities in accordance with the procedures and methods prescribed by applicable statutes.

5. Outsourcing of Data Processing

The Company outsources the processing of personal information as follows to ensure smooth service delivery:

Service Provider Outsourced Tasks Server Location
DigitalOcean, LLC Server hosting and data storage Singapore
Resend, Inc. Transactional email delivery USA
Google LLC OAuth social login authentication USA
Apify Technologies s.r.o. Collection of publicly available Instagram profile and post metrics EU (Czech Republic)

Outsourcing contracts clearly stipulate compliance with personal information protection laws, confidentiality obligations, prohibition of third-party provision, and liability for damages in the event of a security incident.

6. Data Destruction

The Company destroys personal information without delay when it is no longer needed, such as upon expiration of the retention period or fulfillment of the purpose of processing.

A. Destruction Procedure

Information entered by users is transferred to a separate database (or separate documents in the case of paper records) after its purpose has been fulfilled, and is destroyed after a certain period in accordance with internal policies and applicable laws, or immediately.

B. Destruction Methods

  • Electronic files: Permanently deleted using technical methods that prevent the records from being reproduced.
  • Paper documents: Destroyed by shredding or incineration.

7. User Rights

Users (or their legal representatives) may exercise the following rights regarding their personal information at any time:

  • Request to access personal information
  • Request correction of inaccurate information
  • Request deletion of personal information
  • Request suspension of processing

These rights may be exercised by emailing master@thenines.me. The Company will respond and take action without delay.

Rights may also be exercised through a legal representative or authorized agent. In such cases, a power of attorney in the form prescribed by the Enforcement Decree of the Personal Information Protection Act must be submitted.

The Company will verify whether the person making the request is the data subject or an authorized representative before processing any request for access, correction, deletion, or suspension of processing.

8. Cookies and Automatic Data Collection

A. Purpose of Cookies

The Company uses cookies to store and retrieve usage information in order to provide personalized services. Cookies are used to maintain login sessions and configure service settings.

B. Cookie Management

Users have the option to accept or refuse cookies. By adjusting browser settings, users may accept all cookies, require confirmation before each cookie is stored, or refuse all cookies.

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Safari: Preferences → Privacy → Manage website data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data

Please note that refusing cookies may cause difficulty in using certain features of the Service that require login.

9. Protection of Minors

  1. The Company does not accept registrations from individuals under the age of 14. If the Company discovers that personal information of a user under 14 has been collected, it will be deleted immediately and will not be used for any purpose.
  2. Users aged 14 to 17 may register for an account but must obtain verified parental or guardian consent (via email) before applying for any Campaign.

9-2. Data Encryption

The Company encrypts sensitive personal data, including email addresses, phone numbers, and dates of birth, at rest using ActiveRecord::Encryption. All data in transit is protected via SSL/TLS encryption.

10. Chief Privacy Officer (CPO) and Grievance Handling

The Company has designated the following Chief Privacy Officer to oversee the processing of personal information and to handle user complaints and remedies related to personal information:

Chief Privacy Officer (CPO)

Title: X30 Operations Team Manager

Email: master@thenines.me

Users may contact the CPO regarding any inquiries, complaints, or remedies related to personal information protection arising from the use of the Service. The Company will respond and take action without delay.

For additional reporting or consultation regarding personal information infringement, please contact the following organizations:

  • Personal Information Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr / 118
  • Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
  • Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301
  • National Police Agency Cyber Bureau: ecrm.cyber.go.kr / 182

This Privacy Policy is effective as of March 17, 2026. (Revised: March 17, 2026)