Privacy Policy
How 021flow collects, uses, and protects your personal information.
Effective Date: To be announced (2026)
1. Data Controller
- Trade Name
- Zero to One Flow (021flow)
- Representative
- Sungtae Ryu
- [email protected]
[Confirm data protection officer] For a sole proprietorship, confirm whether the representative also acts as the privacy contact, and list a name/contact.
2. Personal Data We Collect
- Account data: email, name or nickname, login identifier
- Authentication data: social-login provider identifiers, token metadata
- Payment-related data: payment status, subscription plan, billing date, receipt/order identifiers, Paddle customer ID or transaction ID
- Service usage data: access logs, IP address, browser/device information, usage, error logs
- Support data: inquiry contents, email, attachments, conversation records
- Information collected via cookies and similar technologies
- Content or files you input into the service
Sensitive payment-method data such as card numbers and CVC are not stored by 021flow directly; they are handled by Paddle (the Merchant of Record) or its payment processors.
3. Purposes of Use
- Account registration and management
- Providing and operating the service
- Verifying paid plan and subscription status
- Payment, billing, refunds, and tax/accounting
- Customer support and notices
- Security, fraud prevention, and incident response
- Service improvement, statistics, and analytics
- Compliance with legal obligations
4. Third Parties & Processors
| Recipient / Processor | Data processed | Purpose | Retention | Cross-border |
|---|---|---|---|---|
| Paddle.com | Order, payment, subscription data, email | Payment, taxes, receipts, refunds, payment support | Statutory transaction-record period | Yes (overseas) |
| Hosting provider | Data required to operate the service | Infrastructure hosting | To be confirmed | To be confirmed |
| Email delivery service | Email, delivery metadata | Auth and notification emails | To be confirmed | To be confirmed |
| Analytics tools | Usage logs, device data | Service analytics and improvement | To be confirmed | To be confirmed |
| Authentication providers | Social-login identifiers | Social-login authentication | To be confirmed | To be confirmed |
| AI API providers | Input data needed for processing | AI feature delivery | To be confirmed | To be confirmed |
| Database/storage providers | Service data | Data storage | To be confirmed | To be confirmed |
[Confirm per-processor details] Verify the actual hosting, email, analytics, auth, AI, and storage providers, the data transferred, retention periods, and destination countries. Do not guess.
5. Cross-Border Transfers
Where we use overseas providers such as Paddle, cloud infrastructure, AI APIs, and analytics tools, personal data may be transferred outside your country. The recipient, destination country, data items, purpose, timing/method, and retention period will be disclosed once confirmed per provider.
[Confirm transfer details per provider] Do not estimate destination countries or retention periods before they are confirmed. You may refuse cross-border transfer, which may limit access to some features.
6. Retention
- As a rule, we delete collected personal data without undue delay when you close your account.
- However, payment/transaction/dispute records may be retained for the statutory period required by applicable law.
- Backup data is deleted on our regular backup cycle.
- A minimum set of records may be retained for fraud prevention for a limited period.
7. Your Rights
You may request access, correction, deletion, restriction of processing, withdrawal of consent, and account closure for your personal data. Submit requests to [email protected].
8. Cookies
- We use cookies and similar technologies to keep you signed in, store preferences, and for analytics.
- Essential cookies are required to provide the service; analytics/marketing cookies are optional.
- You can refuse cookies in your browser settings, but some features may be limited.
[Consider a cookie banner] If you use a consent banner, provide a link to change settings.
9. Security Measures
- Least-privilege access and administrator access controls
- Encryption in transit and at rest
- Access logging and monitoring
- Regular backups and security updates
10. Children’s Privacy
The service is intended for B2B and adult users and is not directed to children under 14 (or the applicable age in your country). If we learn that we have collected a child’s data, we delete it without undue delay.
11. Changes to This Policy
This policy applies from its effective date. We will provide advance notice of changes via in-service notice or email.