Privacy Policy
The Korean version of this document governs. This English text is provided for convenience. Where the two differ, the Korean 개인정보 처리방침 prevails.
SellerMaru ("the Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of the Republic of Korea. It applies to SellerMaru ("the Service").
Effective: 1 September 2026 · Version: 2026-08-14
1. Purposes of processing
- Account registration and management — verifying intent to register, identifying and authenticating the user, maintaining membership, preventing fraudulent use, and delivering notices.
- Providing the Service — collecting and normalizing supplier product and price information, linking a seller's listings to supply products, computing margins and floor prices, and reading marketplace listing information.
- Improving the Service — statistical analysis of entry paths and first actions, in a form that does not identify an individual.
- Security — recording login, signup and password-reset attempts to block abuse and automated attacks.
2. Personal information processed
2.1 Collected at registration
| Type | Items |
|---|---|
| Required | Login identifier, email address, display name, password (stored one-way hashed), language preference, business (team) name, consent records for the Terms and the Privacy Policy (timestamp and the document version consented to), signup source |
| Optional | Marketing-communication consent and its timestamp |
Passwords are stored using PBKDF2-HMAC-SHA256 (600,000 iterations, a random per-user salt). The Company does not store and cannot recover a user's plaintext password.
2.2 Collected via social sign-in
| Provider | Items received |
|---|---|
| Provider account identifier, email address, email-verified flag, name | |
| Naver | Provider account identifier, email address, name or nickname |
| Kakao | Provider account identifier, profile nickname |
⚠ For Kakao sign-in the Company does not request and does not receive an email address. An account created through Kakao therefore has no email address, and the Company cannot contact that user by email until they add a contact address within the Service. Adding one is optional.
2.3 Generated during use
| Item | Description |
|---|---|
| IP address and authentication attempts | Time and outcome of login, signup, password-reset and verification-resend attempts. Processed solely to block abuse and automated attacks |
| Authentication tokens | Single-use tokens for password reset and email verification, stored as hashes rather than in plaintext |
| Usage records | Entry route and first action after entry. Recorded only at business (team) level and containing no personal identifier |
2.4 Submitted by the user
| Item | Description |
|---|---|
| Supplier account credentials | The ID and password for a supplier the user chooses to connect. The password is encrypted with a separately managed key |
| Marketplace connection details | Seller account identifier and API keys. Keys are stored encrypted |
| Commercial information | Listings, selling prices, cost structures, alert thresholds |
See Article 7 of the Terms of Service for how supplier credentials are handled.
3. Retention periods
| Information | Retained |
|---|---|
| Account information (2.1, 2.2) | Until account closure; destroyed without delay once a closure request is received |
| Supplier and marketplace connection details | Until the user disconnects or closes the account |
| Authentication tokens | 30 days after use or expiry |
| Authentication attempt records (incl. IP) | 30 days |
| Usage records | 90 days, then converted to daily statistics that cannot identify an individual or a business, with the originals deleted |
| Statutory retention | As required by law (e.g. three months for access logs under the Protection of Communications Secrets Act) |
⚠ Account closure. The Service does not currently provide a self-service account-closure control. To close an account and have personal information deleted, contact the address in Article 9; the Company will act within 10 days of receipt and notify the user of the outcome.
4. Provision to third parties
The Company does not provide users' personal information to third parties, except where the user has consented in advance, or where required by law or by a lawful request from an investigative authority following statutory procedure.
⚠ Prices obtained using a user's own credentials are not shown to other users. The Company normalizes product and supplier information collected through public channels and makes it available to all users; price information obtained through credentials a user has delegated is shown to that user alone. This is enforced at the database level, not only as policy. See Article 8 of the Terms.
5. Delegation of processing
| Processor | Work | Items |
|---|---|---|
| Sendinblue SAS (Brevo) | Sending authentication and notification email | Email address, display name |
| The Constant Company, LLC (Vultr) | Infrastructure for operating the Service | Information processed in the course of providing the Service |
The Company specifies safeguards in its processing agreements and supervises compliance. Any change of processor or scope will be disclosed through this policy.
6. Transfer of personal information overseas
The Company transfers personal information overseas as set out below. Each transfer is a delegation or storage arrangement made to provide the Service, and is disclosed in this policy in accordance with the Personal Information Protection Act.
① Authentication and notification email
| Recipient | Sendinblue SAS (Brevo) |
| Contact | [email protected] |
| Country | France (European Union) |
| Time and method | Transmitted over the network at the time an authentication or notification email is required |
| Items | Email address, display name |
| Purpose | Account verification, password reset, service notifications |
| Retention | Until the processing agreement ends or the sending purpose is fulfilled |
② Service infrastructure
| Recipient | The Constant Company, LLC (Vultr) |
| Contact | [email protected] · 319 Clematis Street Suite 900, West Palm Beach, FL 33401, USA |
| Country | United States (the provider's place of incorporation) |
| Server location | Republic of Korea (Seoul) — members' personal information is stored on servers located in Korea |
| Time and method | Transmitted over the network and stored while the Service is in use |
| Items | Information processed in the course of providing the Service |
| Purpose | Provision of the server infrastructure the Service runs on |
| Retention | Until the processing agreement ends or the member's account is closed |
Users may refuse the transfer at ①. Doing so makes email delivery impossible, so password reset and email verification become unavailable and the account can be used only through social sign-in. Notify the contact in Article 9 to refuse.
The arrangement at ② is infrastructure essential to providing the Service and the personal information is stored on servers located in Korea, so no separate refusal procedure is offered for it.
7. Rights of the data subject
Users may at any time request access to their personal information, correction of errors, deletion, suspension of processing, or withdrawal of consent. Requests may be made through the account screen in the Service or via the contact in Article 9, and the Company will act without delay. Where correction of an error is requested, the Company will not use or provide the information concerned until the correction is complete. Rights may be exercised through a legal representative or an authorized agent.
8. Destruction of personal information
Where personal information becomes unnecessary — the retention period has elapsed or the purpose has been achieved — the Company destroys it without delay. Electronic files are deleted by technical means that prevent recovery; paper documents are shredded or incinerated. Destruction is approved by the Data Protection Officer.
9. Data Protection Officer
| Name | Wen Yang Ho |
| Title | Chief Technology Officer · Co-Founder |
| Contact | [email protected] |
Users may raise any inquiry, complaint or remedy request concerning personal information with the Data Protection Officer, and the Company will respond without delay.
10. Security measures
- One-way password hashing — PBKDF2-HMAC-SHA256, 600,000 iterations, with a random per-user salt; the plaintext cannot be recovered.
- Encrypted credential storage with key separation — supplier and marketplace credentials are encrypted with a separately managed key held apart from the database and rotated periodically.
- Weak-password rejection — new passwords must meet a minimum length and are checked against a public corpus of breached passwords; matches are refused. The plaintext password is not transmitted externally during this check.
- Access control and data isolation — each user's data is isolated to their business (team) and access to another business's data is prevented at the database level.
- Encryption in transit — all communication with the Service uses HTTPS.
- Attempt limiting and logging — login, signup and password-reset attempts are rate-limited and recorded.
- Session invalidation on reset — resetting a password immediately invalidates all existing sessions for that account.
11. Cookies
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Maintaining the signed-in state | 12 hours |
| Social sign-in state cookie | Preventing tampering during the sign-in flow | 10 minutes |
Both are `HttpOnly` and cannot be read by browser scripts. The Company uses no advertising cookies and no third-party analytics tools. Users may refuse cookies through browser settings, but cannot then use features requiring sign-in.
12. Children under 14
The Service is intended for businesses. It does not accept registration by, and does not collect personal information from, children under 14.
13. Remedies
| Body | Contact |
|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 (www.kopico.go.kr) |
| Privacy Infringement Report Center | 118 (privacy.kisa.or.kr) |
| Supreme Prosecutors' Office, Cybercrime | 1301 (www.spo.go.kr) |
| National Police Agency, Cyber Bureau | 182 (ecrm.police.go.kr) |
14. Changes to this policy
This policy applies from its effective date. Where content is added, removed or amended, the Company will give notice through the Service at least 7 days before the change takes effect, and at least 30 days in advance where user rights are materially affected. A previous version of this policy will be sent on request to [email protected].
version: 2026-08-14