가게한장

Privacy Policy

We use the information needed to build, bill, and support the site.

Scope

Effective July 10, 2026. This Privacy Policy applies to the 가게한장 website, order form, address checks, checkout flow, customer support, website production, and hosting service. This policy covers information we handle directly. Third-party services such as PortOne and its payment gateways, Stripe, domain registrars, email providers, booking services, maps, and social platforms follow their own privacy policies.

Information we collect

We collect information needed to process orders and build the website. This may include business name, owner or manager email, phone number, address, services or menu information, prices, hours, requested domain, existing URL, booking links, social links, style requests, photo or asset links, and other information submitted through forms or email.

Communications and opt out

We may use submitted contact information to reply to inquiries, send order and payment notices, request production materials, provide previews, handle support, and send service-related updates. If we send marketing email, recipients can opt out of future marketing messages by using the unsubscribe method in the message or by emailing Support email must be configured before launch. Opting out of marketing does not stop necessary transactional or service emails.

Payment information

Full card numbers and card authentication data are sent through the PortOne payment window directly to the payment gateway, or handled by Stripe Checkout. This server does not store full card numbers. A PortOne billing key used for renewal may be stored with AES-256-GCM authenticated encryption. We may store the provider name, payment and subscription IDs, encrypted billing key, payment status and amount, selected plan, billing email, and next renewal date to verify payments and manage orders.

Technical information and address checks

For security, troubleshooting, order processing, and payment protection, we may process IP address, browser information, request time, server logs, checkout status, and portions of webhook events. Submitted domains may be checked through RDAP or similar public domain lookup methods. Submitted existing URLs may be requested by the server to confirm that they are reachable.

Cookies and browser storage

This website may use an rws_lang cookie to remember the selected language. After order authentication, the customer portal uses a secure HttpOnly session cookie that remains valid for up to seven days. The server stores only one-way hashes of the 15-minute one-time access link and session token, not their plaintext values. Security and server logs needed to operate checkout and inquiry forms may also be processed. The admin screen may store an access token entered by the administrator in that browser's sessionStorage; that value is separate from the customer portal session. The current site does not include separate ad tracking pixels or behavioral analytics scripts. If analytics, advertising, retargeting, or similar tracking tools are added later, this policy must be updated.

How we use information

We use information to process orders, build websites, check domains or URLs, confirm payment, contact customers, deliver previews, provide hosting and SSL, complete monthly updates, handle refund or cancellation requests, prevent fraud and abuse, maintain security, comply with legal obligations, and improve the service.

Service providers and processors

We do not sell personal information. To provide the service, we may share information with or have it processed by PortOne and its connected payment gateways, optional providers such as Stripe, domain registrars, hosting providers, email notification providers, third-party services requested by the customer, and legal, accounting, or security support providers. These providers process information only for service operations such as payment processing, domain checks or registration, website hosting, email delivery, security, accounting, and dispute handling. We may also share information when needed for legal requests, rights protection, fraud prevention, nonpayment or dispute handling, or a business transfer or restructuring.

Information published on customer websites

Business name, address, phone number, hours, services, menu, prices, photos, social links, and booking links that the customer provides for the website may be published publicly. Customers should not provide personal phone numbers, home addresses, private emails, or sensitive materials that should not be public.

Retention

Order, payment, tax, dispute, refund, and service records may be kept for as long as needed for legal or operational purposes. Customer portal sessions remain valid for up to seven days, and used, expired, or revoked access and session records may remain as hashes for a limited period for security auditing and cleanup. Customer website materials are kept while the service is active. If a deletion request is approved, information that is no longer needed is deleted or anonymized from active service records. Some information may remain for a reasonable period where needed for legal obligations, disputes, accounting, security logs, or backup management.

Security

We use reasonable administrative and technical safeguards to protect information. No internet transmission, email, third-party service, or hosting environment can be guaranteed completely secure. Customers should not send sensitive personal information, card details, passwords, or government identification numbers through ordinary forms or email.

International processing

Customer information may be processed in the United States or other countries where service providers operate. By using the service, the customer understands that information may be processed outside the customer's country.

Rights and requests

Depending on applicable law, customers may request access, correction, deletion, restriction, a copy of their personal information, opt out of marketing, opt out of sale or sharing where applicable, limit certain sensitive personal information uses where applicable, and exercise non-discrimination rights. We do not sell personal information. Information needed for payment, tax, security, legal obligations, service delivery, or dispute handling may not be deleted immediately. Requests should be sent from the billing email on the order to Support email must be configured before launch.

Privacy contact and complaints

Requests for access, correction, deletion, opt out, complaints, and other privacy questions can be sent to Legal name must be configured before launch at Support email must be configured before launch. Mailing address: Mailing address must be configured before launch.

Children's privacy

This service is for businesses and is not directed to children. We do not knowingly collect children's personal information.

Changes

We may update this policy when the service, law, payment, or operating practices change. Material changes will be shown by the latest effective date posted on the website.