Table of Contents

LEGAL

Privacy Policy

v2Effective Date 2026-07-28

IntelliEffect (the "Company") complies with the Personal Information Protection Act (PIPA, Korea) and other applicable laws, and establishes and discloses the following Privacy Policy in order to safely process users' personal information. This Policy applies to the Castera service operated by the Company.

At a Glance

Information We Collect

Account information such as email address and display name, and service usage records — we collect only the minimum necessary to provide the Service.

Purpose of Use

Used to provide the Service, including member authentication, Creator–Brand matching, contract execution, payment, and settlement.

Retention Period

Destroyed without delay upon withdrawal of membership. Only information subject to a statutory retention obligation is retained as an exception.

Contact

For privacy-related inquiries, please contact dev@intellieffect.com.

1. Personal Information Collected and Methods of Collection

The Company collects the following personal information during member registration, provision of the Service, and the payment/settlement process.

1. Personal Information Collected and Methods of Collection
CategoryApplicable ToItems CollectedTime of Collection
RequiredAll MembersEmail address, password (for email registration · stored using one-way encryption), display name, role information (Creator/Brand)At registration and onboarding
RequiredWhen using social loginSocial account identifier, email address, profile name (provided by Google · LINE)When linking a social account
RequiredCreator MembersSNS handle in operation (account URL), area of activityAt Creator registration
RequiredBrand MembersCompany (brand) name, contact person information, industryAt Brand registration
RequiredWhen using payment/settlementPayment approval information (original payment instrument data not retained), settlement account information, tax invoice issuance informationAt payment/settlement
Automatically collectedAll usersAccess logs, device/browser information, service usage records, error logsDuring use of the Service

The original data of payment instruments, such as card numbers, is processed by the electronic payment service provider (Toss Payments), and the Company does not store it.

2. Purposes of Processing Personal Information

Personal information collected is processed for the following purposes, and where the purpose changes, separate consent will be obtained in accordance with applicable laws.

  1. Member registration, authentication, and management — identity verification, prevention of fraudulent use, and various notices
  2. Provision of the Service — Creator–Brand matching, support for executing and performing Campaign contracts, inter-Member messaging functions
  3. Payment processing, escrow deposit, and settlement processing
  4. Maintaining a safe transaction environment — preventing circumvention transactions, responding to disputes, protecting accounts
  5. Service improvement and statistical analysis (in a form that does not identify individuals)
  6. Fulfilling obligations under applicable laws

Where personal information is used for marketing purposes, separate consent will be obtained, and use of the Service is not restricted if consent is not given.

3. Retention and Use Period of Personal Information

In principle, the Company destroys personal information without delay upon a Member's withdrawal. However, in the following cases, the information is stored separately for the relevant period before being destroyed.

3. Retention and Use Period of Personal Information
Basis for RetentionItems RetainedPeriod
Act on the Consumer Protection in Electronic Commerce, etc. (Korea)Records relating to contracts or withdrawal of subscription5 years
Act on the Consumer Protection in Electronic Commerce, etc. (Korea)Records relating to payment and supply of goods, etc.5 years
Act on the Consumer Protection in Electronic Commerce, etc. (Korea)Records relating to consumer complaints or dispute handling3 years
Protection of Communications Secrets Act (Korea)Service access records3 months
Internal policy (fraud prevention)Records relating to fraudulent registration or restriction of use1 year after withdrawal

A Creator's SNS handle is deleted within 30 days of the Member's withdrawal, in accordance with the SNS Handle Non-Disclosure Policy.

4. Provision of Personal Information to Third Parties

In principle, the Company does not provide users' personal information to outside parties, and provides it only where the user has given prior consent or there is a legal basis for doing so.

Given the nature of the Service, the following provision occurs during the process of executing a Campaign contract.

4. Provision of Personal Information to Third Parties
RecipientItems ProvidedPurpose of ProvisionRetention/Use Period
The counterparty Brand Member with whom a Campaign contract has been executedCreator's SNS handlePerformance of the executed Campaign contract — disclosed upon execution of the contract and full deposit of the payment into escrowUntil the purpose of the contract is achieved

Before a contract is executed, a Creator's SNS handle is not provided to any advertiser under any circumstances. Please refer to the SNS Handle Non-Disclosure Policy for details.

5. Outsourcing of Personal Information Processing

To provide a stable Service, the Company outsources personal information processing tasks as follows.

5. Outsourcing of Personal Information Processing
ProcessorOutsourced Task
Supabase, Inc.Database operation and member authentication infrastructure
Vercel Inc.Service hosting and web analytics (cookieless)
Toss Payments Co., Ltd.Electronic payment processing (including escrow)
Functional Software, Inc. (Sentry)Service error monitoring

When entering into an outsourcing agreement, the Company stipulates compliance with applicable personal information protection laws, restrictions on re-outsourcing, and technical and administrative protective measures, and supervises the processor.

6. Overseas Transfer of Personal Information

The servers of some cloud services used by the Company are located overseas, and personal information is transferred overseas as follows in the course of using the Service.

6. Overseas Transfer of Personal Information
RecipientCountryItems TransferredMethod/Time of TransferRetention Period
Supabase, Inc.United States, etc.Account information, service usage dataTransmitted and stored via the information and communications network when using the ServiceUntil termination of the outsourcing agreement or withdrawal of membership
Vercel Inc.United States, etc.Access records, de-identified web analytics dataTransmitted via the information and communications network when accessing the ServiceUntil the purpose of collection is achieved
Functional Software, Inc. (Sentry)United StatesError logs (identifying information minimized)Transmitted via the information and communications network when an error occursUntil the purpose of collection is achieved

Users may refuse the overseas transfer of their personal information. However, because overseas transfer is essential infrastructure for providing the Service, use of the Service may be restricted if refused. A refusal request may be made to dev@intellieffect.com.

7. Procedure and Method for Destruction of Personal Information

The Company destroys personal information without delay once it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.

Information in electronic file form is deleted using a technical method that prevents recovery, and paper documents are destroyed by shredding or incineration. Information that must be retained under applicable law is stored separately in a separate storage space and destroyed immediately upon expiry of the retention period.

8. Users' Rights and How to Exercise Them

Users may exercise the following rights against the Company at any time, and the Company shall take action without delay within the period prescribed by applicable law.

Rights may be exercised through the settings screen within the Service or by email (dev@intellieffect.com), and may also be exercised through a legal representative or an authorized agent. In such a case, a power of attorney in accordance with applicable law must be submitted.

  1. Request to access personal information
  2. Request for correction where there is an error
  3. Request for deletion
  4. Request to suspend processing
  5. Withdrawal of consent to the collection and use of personal information (withdrawal of membership)

The exercise of rights may be restricted where applicable law mandates the collection or retention of the relevant personal information, and in such a case the reason will be provided.

9. Cookies and Analytics Tools

The Company uses cookies essential to providing the Service, such as for maintaining login sessions. Essential cookies are required for use of the Service, and if blocked in the browser, some functions such as login may not be available.

The Company uses Vercel Web Analytics and Speed Insights to understand service usage (visitor counts, page views, referral sources) and web performance (loading speed, etc.). These tools do not use cookies (cookieless) and do not collect information that can identify an individual user.

The Company does not use third-party behavioral information collection tools for targeted advertising purposes (such as advertising pixels).

Users can block the collection of analytics scripts by enabling their browser's tracking prevention features (such as Safari's 'Prevent Cross-Site Tracking,' Chrome's 'Block third-party cookies,' or Firefox's 'Enhanced Tracking Protection') or by using a content-blocking extension. This has no effect on use of the Service.

10. Measures to Ensure the Safety of Personal Information

The Company takes the following measures to ensure the safety of personal information.

  1. Administrative measures — establishing and implementing an internal management plan, minimizing access privileges to personal information, and managing access records
  2. Technical measures — one-way encrypted storage of passwords, encryption of data in transit (TLS), database access control, and application of Row Level Security
  3. Physical measures — utilizing the cloud provider's physical access controls and security certification systems
  4. Minimizing access privileges to, and managing access logs for, highly sensitive information such as SNS handles

11. Data Protection Officer and Contact

The Company designates a Data Protection Officer as set out below, who oversees personal information processing and handles users' complaints and remedies relating to the processing of personal information.

Users may direct any inquiry, complaint, or request for remedy relating to personal information arising from use of the Service to the contact below, and the Company will respond and address it without delay.

11. Data Protection Officer and Contact
CategoryDetails
Data Protection OfficerCEO of IntelliEffect
Contact Emaildev@intellieffect.com

12. Remedies for Infringement of Rights

Users who need to report or consult regarding an infringement of personal information may contact the following institutions.

12. Remedies for Infringement of Rights
InstitutionContactWebsite
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
KISA Privacy Center (Korea Internet & Security Agency)118 (no area code)privacy.kisa.or.kr
Supreme Prosecutors' Office Cyber Investigation Division1301 (no area code)www.spo.go.kr
National Police Agency Cyber Investigation Bureau182 (no area code)ecrm.police.go.kr

13. Duty to Notify and Amendments

Where the content of this Privacy Policy is added, deleted, or amended, notice will be given through the Service's announcements starting 7 days before the effective date. However, where an amendment materially affects users' rights, such as a change in the items collected or provision to third parties, notice will be given 30 days before the effective date, and separate consent will be obtained again where necessary.

Data Protection Officer & Contact

Data Protection Officer

CEO of IntelliEffect

dev@intellieffect.com

Handles inquiries and requests to access, correct, delete, and suspend processing of personal information.

Revision History

  • v2 · 2026-07-28Complete revision — reorganized the table of items collected; added outsourcing of processing, overseas transfer, provision to third parties, safety measures, and remedies for infringement of rights
  • v1 · 2026-05-18Initial enactment

This document is currently under legal review, and some content may be adjusted based on the review outcome.