Privacy Policy

How 021flow collects, uses, and protects your personal information.

Effective Date: To be announced (2026)

1. Data Controller

Trade Name
Zero to One Flow (021flow)
Representative
Sungtae Ryu

[Confirm data protection officer] For a sole proprietorship, confirm whether the representative also acts as the privacy contact, and list a name/contact.

2. Personal Data We Collect

  • Account data: email, name or nickname, login identifier
  • Authentication data: social-login provider identifiers, token metadata
  • Payment-related data: payment status, subscription plan, billing date, receipt/order identifiers, Paddle customer ID or transaction ID
  • Service usage data: access logs, IP address, browser/device information, usage, error logs
  • Support data: inquiry contents, email, attachments, conversation records
  • Information collected via cookies and similar technologies
  • Content or files you input into the service

Sensitive payment-method data such as card numbers and CVC are not stored by 021flow directly; they are handled by Paddle (the Merchant of Record) or its payment processors.

3. Purposes of Use

  • Account registration and management
  • Providing and operating the service
  • Verifying paid plan and subscription status
  • Payment, billing, refunds, and tax/accounting
  • Customer support and notices
  • Security, fraud prevention, and incident response
  • Service improvement, statistics, and analytics
  • Compliance with legal obligations

4. Third Parties & Processors

Recipient / ProcessorData processedPurposeRetentionCross-border
Paddle.comOrder, payment, subscription data, emailPayment, taxes, receipts, refunds, payment supportStatutory transaction-record periodYes (overseas)
Hosting providerData required to operate the serviceInfrastructure hostingTo be confirmedTo be confirmed
Email delivery serviceEmail, delivery metadataAuth and notification emailsTo be confirmedTo be confirmed
Analytics toolsUsage logs, device dataService analytics and improvementTo be confirmedTo be confirmed
Authentication providersSocial-login identifiersSocial-login authenticationTo be confirmedTo be confirmed
AI API providersInput data needed for processingAI feature deliveryTo be confirmedTo be confirmed
Database/storage providersService dataData storageTo be confirmedTo be confirmed

[Confirm per-processor details] Verify the actual hosting, email, analytics, auth, AI, and storage providers, the data transferred, retention periods, and destination countries. Do not guess.

5. Cross-Border Transfers

Where we use overseas providers such as Paddle, cloud infrastructure, AI APIs, and analytics tools, personal data may be transferred outside your country. The recipient, destination country, data items, purpose, timing/method, and retention period will be disclosed once confirmed per provider.

[Confirm transfer details per provider] Do not estimate destination countries or retention periods before they are confirmed. You may refuse cross-border transfer, which may limit access to some features.

6. Retention

  • As a rule, we delete collected personal data without undue delay when you close your account.
  • However, payment/transaction/dispute records may be retained for the statutory period required by applicable law.
  • Backup data is deleted on our regular backup cycle.
  • A minimum set of records may be retained for fraud prevention for a limited period.

7. Your Rights

You may request access, correction, deletion, restriction of processing, withdrawal of consent, and account closure for your personal data. Submit requests to [email protected].

8. Cookies

  • We use cookies and similar technologies to keep you signed in, store preferences, and for analytics.
  • Essential cookies are required to provide the service; analytics/marketing cookies are optional.
  • You can refuse cookies in your browser settings, but some features may be limited.

[Consider a cookie banner] If you use a consent banner, provide a link to change settings.

9. Security Measures

  • Least-privilege access and administrator access controls
  • Encryption in transit and at rest
  • Access logging and monitoring
  • Regular backups and security updates

10. Children’s Privacy

The service is intended for B2B and adult users and is not directed to children under 14 (or the applicable age in your country). If we learn that we have collected a child’s data, we delete it without undue delay.

11. Changes to This Policy

This policy applies from its effective date. We will provide advance notice of changes via in-service notice or email.

HawkEyeOps — Cross-channel ad ops, SEO, and GEO