Privacy Policy

1. Purposes of processing personal data

JSOFT (the “Company”) processes personal data to provide AIBIZAP and does not use it for purposes other than those stated below. ① Confirming intent to register, identifying and authenticating users, and maintaining user status ② Processing payments for goods or services and providing the service ③ Handling inquiries, complaints, remedies, and operational notices

2. Processing and retention periods

The Company processes and retains personal data for the period agreed to by the data subject or required by applicable law. ① Customer registration and management: until termination of the service agreement or membership, except where outstanding claims or obligations require retention until settlement. ② Records of contracts, withdrawal, payment, and supply in e-commerce: retained for five years as required by applicable law.

3. Rights and obligations of data subjects

A data subject may exercise the following privacy rights against the Company at any time. 1. Request access to personal data 2. Request correction of errors 3. Request deletion of personal data 4. Request suspension of processing

For privacy questions or deletion requests, please use the Contact page.

4. Categories of personal data processed

The Company may process the following information to the extent necessary to provide the service. ① Service use and customer management: name and email address ② Payment processing and confirmation: order ID and payment authentication result ③ Automatically generated data: access logs, cookies, usage records, device and browser information

Google OAuth / GooglePlayEarning

  • Requested scopes: openid for sign-in, https://www.googleapis.com/auth/userinfo.email for your Google account email, and https://www.googleapis.com/auth/devstorage.read_only for read-only access to Google Cloud Storage
  • Accessed data: Google account email, OAuth access and refresh tokens, GCS object names, paths, sizes, update timestamps, and the report files you choose to process
  • Use: account authentication, report listing and download, settlement preview, and Excel export

Payment service

For Toss Payments, we store only the order ID and authentication result needed to confirm payment status. We do not store card numbers or full payment credentials.

5. Destruction of personal data

The Company destroys personal data without undue delay after the processing purpose has been fulfilled. Procedure: information that must be retained separately is kept for the period required by internal policy or law and is not used for other purposes unless permitted by law. Deadline: data is destroyed within five days after the retention period expires or the data becomes unnecessary. Method: electronic files are deleted so they cannot be recovered, and paper records are shredded or incinerated.

6. Cookies and automatic collection

The Company may use cookies that store and retrieve usage information for personalized services and analytics. A cookie is a small amount of data sent by a web server to a browser. Purpose: to understand visits, usage patterns, popular features, and secure access and provide optimized information. Refusal: users may block cookies in browser privacy or site settings. Some personalized features may not work properly if cookies are blocked.

Google Tag Manager may load analytics or advertising tags configured by the site operator. Google AdSense may process usage, device, and advertising identifiers for ad delivery.

7. Privacy officer

The Company designates the following privacy officer and department to oversee personal-data processing and handle privacy inquiries, complaints, and remedies. Privacy officer: Park Jaehwan Privacy department: Development Team Contact person: Park Jaehwan

[email protected]

8. Changes to this Privacy Policy

This Privacy Policy applies from its effective date. Material additions, deletions, or corrections resulting from law or internal policy will generally be announced through the service at least seven days before they take effect.

9. Safeguards for personal data

The Company implements technical, administrative, and physical safeguards under applicable privacy laws. 1. Regular internal audits 2. Minimizing and training personnel who handle personal data 3. Establishing and implementing an internal management plan 4. Installing, updating, and inspecting security software against hacking and malware 5. Encrypting important personal data and data in transit 6. Retaining access logs and preventing alteration 7. Managing access rights and blocking unauthorized external access 8. Securely storing documents and removable media containing personal data 9. Controlling unauthorized entry to physical data-storage locations

10. Google user data sharing and protection

We process Google user data on our servers only to provide the GooglePlayEarning features described in this policy. We send it to Google only when making the Google OAuth or Google Cloud Storage API requests required for authentication and the report workflow. We do not sell, rent, or disclose Google user data to advertisers, data brokers, or other third parties, and we do not use it for targeted advertising, profiling, credit assessment, or training generalized AI or machine-learning models. We may disclose information only when required by law or necessary to protect the security of the service.

OAuth access and refresh tokens are kept in server-side session storage, and the browser receives only HttpOnly authentication and session cookies. HTTPS, access controls, and session expiration are used to protect Google user data in transit and during processing. We do not write OAuth tokens to application logs.