Privacy Policy
In effect from September 2, 2026
This is a translation of the Korean original. If the two differ, the Korean text prevails. For questions, contact dev@impactstation.kr.
Impact Station Co., Ltd. (the "Company") treats your personal data with care and complies with the Personal Information Protection Act of Korea and other applicable laws. This policy describes what personal data we process, for what purpose, how long we keep it, and how we destroy it.
| Controller | Detail |
|---|---|
| Company name | Impact Station Co., Ltd. |
| Representative | Song Sanghoon |
| Business registration number | 683-86-00599 |
| Address | 901, 23 Gukhoe-daero 66-gil, Yeongdeungpo-gu, Seoul, Republic of Korea |
This policy is published at all times at https://contentrip.com/en/privacy.
Article 1 Categories of personal data we process
We process only the minimum personal data needed to provide the service.
1-1. Collected automatically when you sign up or sign in
Values that the provider passes to the Company when you sign in with a social account.
| Item | Detail |
|---|---|
| Email address | Account identification |
| Name | Default for your initial display name |
| Profile picture | We copy the image the provider gives us into our own storage — we do not store the original URL |
| Email verification time | Value provided by the provider |
| Social account identifier · authentication token | Needed to keep you signed in |
| Sign-in method | Where your data goes |
|---|---|
| United States — explained in Article 6 | |
| Apple | United States — explained in Article 6 |
| Kakao | Republic of Korea — it does not leave the country |
| Email and password | It does not go anywhere |
1-2. Entered by you
You can use the service without entering these. They appear on your public profile.
| Group | Items |
|---|---|
| Profile | Display name · profile picture · bio · handle (generated automatically at sign-up) |
| Creator profile | Country and city of activity · specialties · tools used · languages · roles · whether you accept bank transfers (for display) · collaboration terms (available hours · time zone · team size · external links) |
| Posts and comments | Body text · attached images |
| Commissions | Commission message (255 characters) · reference links · budget · preferred region |
| Reports | Reason for the report · detailed description |
1-3. Generated while you use the service
| Item | Detail |
|---|---|
| Playback records | Playback start, progress and end events; resume position |
| View records | Profile views |
| Recommendation impression records | Which recommendations were shown and clicked |
| Relationship records | Follows · blocks · favourites · likes |
| Notifications | Notification title, body and sender |
Activity recorded while signed out is not personal data. Records from browsing without signing in contain no value that points to a person — they remain only as aggregate data with no way to identify anyone.
1-4. What we do not collect today
The items below are not collected because no screen exists for them. We will amend this policy before opening any such feature.
- Resident registration numbers, passport numbers and other unique identifiers — there is no place to store them
- Bank account numbers, payee details and other payment information — there is no place to store them
- Sensitive data such as beliefs, health or sex life — there is no place to store them
- Date of birth · age — there is no place to store them
- IP addresses · browser information — not stored in the Company's database
- Company details (company name, business registration number, contact person) — a field exists but there is no input screen
- App push tokens · search queries · electronic signature records — fields exist but nothing is recorded
- Payment information — payments are not connected
Article 2 Purposes of processing
| Purpose | Data processed |
|---|---|
| Identifying members · keeping you signed in | Email · social account identifier · authentication token |
| Showing public profiles | Display name · profile picture · handle · bio · creator profile |
| Ranking content · composing the home screen | Playback and view records (aggregated) |
| Resuming playback | Playback position |
| Showing recommendations and measuring their performance | Recommendation impression and click records |
| Social features such as follow and block | Relationship records |
| Sending notifications | Notification recipients and content |
| Receiving and handling reports | Reason · details · outcome |
| Receiving and brokering commissions | Commission content · budget · region |
| Audit trail of operator actions | Who acted, on what, why, and with what result |
| Meeting legal obligations (transaction and tax records) | Orders · payments · tax invoices · settlement records |
Article 3 Processing and retention periods
3-1. Principle
Member data is kept for as long as membership continues and destroyed under the procedure in Article 7 after you request withdrawal.
3-2. Kept longer because the law requires it
Transaction and tax records are retained rather than destroyed, as required by law. These records are stored and managed separately from other personal data.
We retain records as if we were an intermediary in mail-order sales. The proviso to Decree The E-Commerce Decree limits an intermediary's retention scope to "records processed through its own information processing system", but the Company retains the whole table above rather than that narrower scope — retaining more broadly satisfies the statutory duty under either reading. The retention periods are the same either way.
3-3. Retention of service usage records
Records left behind as you use the service are made impossible to attribute to a person once the periods below pass. The records remain as statistics, but the values linking them to you are erased.
Deleting your account is handled regardless of the periods above. After withdrawal we destroy data following a 30-day grace period, and the identifiers in usage records are erased at the same time (Article 7).
These periods are kept by code that runs every hour, not by a promise on paper. Writing a period into a policy with no procedure to erase makes the policy itself a promise that is not kept — so this article was written after the deletion and anonymisation procedures existed.
Article 4 Provision to third parties
The Company does not provide your personal data to third parties. We do entrust processing to the extent needed to operate the service; that is described in Articles 5 and 6.
Article 5 Entrustment of processing
The database, web servers and file storage are processed domestically (Seoul). Only the rows marked "Overseas" above leave the country; details are in Article 6.
Article 6 Transfers of personal data overseas
6-0. Basis for the transfer, and why we do not seek separate consent
To provide the service the Company entrusts the processing and storage of personal data to overseas providers. This is entrustment and storage necessary to perform the contract with you, and because the matters below are disclosed in this policy, we do not seek separate consent.
For each recipient we set out the five points below.
6-1. Google LLC — social sign-in authentication · profile image hosting
There are two paths for this transfer.
| Item | Detail |
|---|---|
| What is transferred | (a) Sign-in — your IP address and browser information at the moment you are taken to the Google sign-in screen (collected by Google directly) (b) Profile pictures do not travel by this path — we copy the picture into our own storage at sign-up, so a viewer's IP address never reaches Google |
| Country · when · how | United States and others (countries where Google operates) / at the moment of a sign-in attempt / HTTPS request |
| Recipient · contact | Google LLC — googlekrsupport@google.com (the contact given in Google's Korean privacy policy) |
| Purpose · retention | Sign-in authentication · profile image delivery / Google does not publish a single retention period — it varies by data type and user setting. For as long as the Company offers Google as a sign-in method |
| How to refuse | You can sign up with a different method — using Kakao (domestic) or email and password sends nothing to Google |
6-2. Apple Inc. — social sign-in authentication
| Item | Detail |
|---|---|
| What is transferred | Your IP address and device information at the moment you are taken to the Apple sign-in screen (collected by Apple directly) |
| Country · when · how | United States — Apple states that it stores personal data gathered worldwide with Apple Inc. in the United States / at the moment of a sign-in attempt / HTTPS request |
| Recipient · contact | Apple Inc. — https://www.apple.com/legal/privacy/contact/ (the privacy contact Apple provides) |
| Purpose · retention | Sign-in authentication / Apple likewise does not publish a single retention period. For as long as the Company offers Apple sign-in |
| How to refuse | Signing up with another method (Kakao, email) sends nothing to Apple |
During sign-in the Company does not send these providers any identifier that points to you. The only value carried in a sign-in request is a temporary value confirming that the request started on our screen; it contains no member number, email address or anything similar.
Apple's private email relay runs in the opposite direction. Apple gives the Company an anonymous address; it is not personal data the Company sends to Apple. That anonymous address is stored by the Company, so it appears among the items collected in Article 1.
6-3. Mux, Inc. — video encoding · streaming
| Item | Detail |
|---|---|
| What is transferred | The original video uploaded by a creator, and the viewer's IP address and playback request information when a video is played The Company does not send user identifiers to Mux |
| Country · when · how | United States / at upload · at playback / the browser uploads to and requests playback from Mux directly |
| Recipient · contact | Mux, Inc. (88 Stevenson Street, San Francisco, CA 94105, USA) — privacy@mux.com |
| Purpose · retention | Video encoding and stream delivery / Mux likewise does not publish a single retention period. Original videos are kept until the Company deletes the asset; viewer IP addresses follow Mux's own policy |
| How to refuse | If you do not play videos, your IP address is not passed on. Watching videos is however the core of the service, so this makes it hard to use in practice. A creator who does not upload a video transfers no original |
6-4. Amazon Web Services, Inc. — image delivery (CDN)
| Item | Detail |
|---|---|
| What is transferred | Profile pictures · content thumbnails · images attached to posts (public files only) |
| Country · when · how | CDN servers in a country near you / on the first request for a file / temporarily cached after HTTPS delivery |
| Recipient · contact | Amazon Web Services, Inc. — https://aws.amazon.com/contact-us/ |
| Purpose · retention | Faster delivery. Deleted when the cache expires; the original stays in Korea |
| How to refuse | To refuse this transfer you may withdraw your membership, which destroys the files. Note that if you refuse, profile pictures and thumbnails will not be visible |
Storage is domestic. Originals are in the Seoul region; what goes abroad is a copy for delivery.
Files that require sign-in do not travel by this path — original videos and settlement statements open only through signed URLs and do not pass through the CDN.
Whether to upload a potentially sensitive image such as a photograph of your face is your choice. We point out that profile pictures appear on public screens and therefore take this path.
6-5. GitHub, Inc. — running scheduled batch jobs
| Item | Detail |
|---|---|
| What is transferred | Personal data within the scope the batch handles (accounts due for destruction, records due for aggregation). GitHub does not store it |
| Country · when · how | United States (GitHub-hosted runners) / hourly aggregation batch · daily destruction batch at 03:00 Korea time / the runner connects to the database directly |
| Recipient · contact | GitHub, Inc. (88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA) — dpo@github.com |
| Purpose · retention | Providing an execution environment for scheduled batches / results are not stored. Execution logs are retained by GitHub for 90 days by default (configurable) |
| How to refuse | See 6-6 below |
6-6. How to refuse an overseas transfer, and its effect (common)
If you do not want these transfers you may stop them by withdrawing your membership. The withdrawal procedure is in Article 7.
- You cannot refuse individual processors. The providers above are infrastructure the service runs on; remove any one and the service does not work.
- If you refuse, you cannot use the service. Sign-up, sign-in, video playback and profile display all run on that infrastructure.
- Some transfers can be partly avoided by not using the feature, as noted for Mux and the CDN above (uploading your own profile picture, not playing videos).
Article 7 Procedure and method of destruction
7-1. Procedure
- You request withdrawal (account deletion).
- A 30-day grace period applies. You may cancel the request during this time.
- Once the grace period ends, a destruction job that runs daily at 03:00 Korea time processes it.
When destruction is deferred — if any of the following applies we wait until it is resolved. Once resolved, it continues automatically without a new request. The withdrawal screen tells you which reason caused the deferral.
| Reason | How it resolves |
|---|---|
| A project is in progress | Resolves automatically when the project ends |
| Settlement money is unpaid | Resolves automatically when settlement completes |
| A report or dispute is being handled | Resolves automatically when handling completes |
| You have an active subscription | You must cancel it yourself |
| A refund deduction balance remains | Please contact support |
7-2. Method — this is destruction of identifying data followed by anonymisation, not "deletion"
When you withdraw, we erase the values that point to a person and make the author unidentifiable in records that remain, such as posts and comments. What is erased and what remains:
Posts, comments and reviews you wrote are not deleted and remain. Following the author leads only to the emptied profile described above.
7-3. Records of destruction
Destruction is carried out by a method that cannot be reversed, and matters concerning destruction are recorded and managed. Afterwards the Data Protection Officer verifies the result.
7-4. Retained under the law
The transaction and tax records described in Article 3 are not destroyed but stored separately.
Article 8 Rights of data subjects and legal representatives, and how to exercise them
You may exercise the following rights at any time.
| Right | Detail |
|---|---|
| Access | Confirm the personal data the Company processes about you |
| Correction · deletion | Ask us to correct or delete inaccurate content |
| Suspension of processing | Ask us to stop processing your personal data |
| Withdrawal of consent | Withdraw consent for data processed on the basis of consent |
- You can edit profile information yourself on the profile edit screen.
- For anything else, please write to dev@impactstation.kr.
- We handle requests within 10 days and tell you the outcome.
- If we refuse a request or cannot act on it, we tell you the reason without delay.
- You may also make requests through a legal representative or an authorised agent.
Article 9 Automatic collection devices (cookies)
The Company uses the following cookies.
How to refuse — you can refuse cookie storage or delete stored cookies in your browser settings. Note that if you refuse the sign-in cookie you cannot use features that require signing in.
The Company does not use third-party cookies for advertising or analytics.
Article 10 Measures to secure personal data
The Company takes the following measures.
| Measure | Detail |
|---|---|
| Access control at the database level | Row-level security policies apply to the main tables holding member data, so the database itself ensures only your own data is returned |
| Separation of connection privileges | The account the service uses and the account for administrative work are separated, so the service account cannot bypass security policies |
| Tamper protection for consent records | Consent and withdrawal records are append-only; the service account cannot modify or delete them |
| Audit trail of operator actions | Operator actions record who, what, why and with what result, and are neither modified nor deleted |
| Protection of sign-in data | The sign-in cookie is set so browser scripts cannot read it |
| Access control for video | Video playback URLs open only with a signed token valid for six hours |
| Encryption in transit | All external transmission uses encrypted connections (HTTPS, encrypted database connections) |
| Internal management plan | We maintain and operate an internal management plan for handling personal data safely |
| Access log retention | What operators did with personal data is recorded and not erased. Service access logs are kept for one year |
| Encryption at rest | The database and file storage are encrypted at rest. Passwords are never stored in plain text and are kept only in an irreversible form |
| Malware protection · physical access control | Servers run in the cloud provider's data centres and the runtime is replaced with a fresh image on every deployment. We operate no server room of our own |
We do not process unique identifiers (such as resident registration numbers) or sensitive data. There is no place to store them, so no separate encryption obligation arises for them.
The specifics of these measures are recorded in our internal management plan. We can demonstrate them from that document if a supervisory authority asks.
Article 11 Items that do not apply
Items the law requires "only where applicable". They do not apply.
11-1. Possibility of sensitive data being made public and how to opt out
The Company does not process sensitive data. There is no place to store it.
11-2. Processing of pseudonymised data
The Company does not process pseudonymised data.
11-3. Criteria for additional use or provision
The Company does not use or provide data beyond the purposes for which it was collected.
11-4. Country names where personal data of Korean data subjects is collected directly from abroad
The Company has no flow that collects directly from abroad.
Article 12 Personal data of children under 14
The Company does not process the personal data of children under the age of 14. This is the same wherever you live.
- After sign-up, before you first use the service, we confirm that you are 14 or older; until you do, you cannot use the service.
- We record only the fact and time of that confirmation. We neither ask for nor store your date of birth or age — the principle of not holding unnecessary data (Article 1) applies here too.
Different countries set different ages, and 14 satisfies all of them together.
On GDPR Article 8 — that provision sets an age for processing where consent is the legal basis (it points explicitly to Article 6(1)(a)). The Company processes data to provide the service on the basis of performance of a contract (see the table in Article 15-2), so the age requirement in that provision does not apply directly. We therefore do not vary the age by member state on screen and keep a single threshold of 14.
If we learn that a user is under 14 we destroy that account's personal data without delay. The child or their legal representative may tell us through the contact point in Article 13.
This confirmation is self-declared and does not go through an identity verification agency. The law does not specify a verification method, so we use this approach for now; if stronger verification becomes necessary we will change it and amend this article at the same time.
Article 13 Data Protection Officer and contact
13-1. Data Protection Officer
| Item | Value |
|---|---|
| Name | Song Sanghoon |
| Position | Representative [Representative] |
| Department | — (no separate department) |
| Contact | dev@impactstation.kr |
13-2. Department receiving and handling access requests
There is no separate department; the Data Protection Officer (Representative Song Sanghoon) receives and handles requests directly. The contact point is dev@impactstation.kr.
13-3. Domestic representative
Not applicable. The Company is a Korean corporation (Impact Station Co., Ltd.) — the duty to appoint a domestic representative applies to businesses with no address or place of business in Korea.
Article 14 Remedies for infringement of rights
If you need help with a personal data infringement, you may contact the following bodies.
You may also file an administrative appeal under the Administrative Appeals Act if you object to a controller's disposition.
Article 15 Changes to this policy
If this policy changes we will tell you through service notices from seven days before it takes effect. For important changes we will tell you from 30 days before.
You can compare what changed, before and after, in the revision history.
Revision history
Article 15-2 Provisions for users outside Korea
The service can be used in many countries. Depending on where you live, the personal data law of that country also applies, and this article sets out what changes then.
The storage location is the same wherever you live — the Republic of Korea (Seoul). From the moment your personal data reaches the Company it is processed as described in Articles 5 and 6.
15-2-1. If you are in the European Economic Area (EEA) or the United Kingdom
The Company offers the service to residents of the EEA and the United Kingdom, so the GDPR (and UK GDPR) applies. The Company is the controller under those laws.
Legal bases for processing — the basis depends on what data is processed and why.
| What we process | Legal basis |
|---|---|
| Providing the service: account creation, sign-in, video playback, profile display | Performance of a contract |
| Maintaining security, handling abuse and reports, aggregation to improve the service | Legitimate interests — we have balanced these against your rights |
| Retaining transaction and tax records | Legal obligation |
Rights you can exercise — send requests to dev@impactstation.kr. We handle them and tell you the outcome within one month.
| Right | Detail |
|---|---|
| Access | Receive a copy of the personal data we process about you |
| Rectification | Ask us to correct inaccurate content |
| Erasure | Ask us to delete it (the "right to be forgotten") |
| Restriction of processing | Ask us to pause processing |
| Portability | Receive your data in a machine-readable format and move it elsewhere |
| Objection | Object to processing based on legitimate interests |
| Withdrawal of consent | Withdraw consent at any time. Processing before withdrawal remains valid |
- You may lodge a complaint with a supervisory authority. In the EEA this is the authority of your member state; in the United Kingdom it is the Information Commissioner's Office (ICO, ico.org.uk).
- We do not carry out processing that produces legal effects concerning you based solely on automated decision-making.
Transfers to the Republic of Korea — the European Commission adopted an adequacy decision for the Republic of Korea in December 2021. Transferring personal data from the EEA to Korea therefore requires no additional safeguard such as standard contractual clauses. The United Kingdom likewise recognises the Republic of Korea as providing adequate protection.
Contact — GDPR enquiries and requests to exercise rights are received at dev@impactstation.kr. The Data Protection Officer is named in Article 13.
15-2-2. If you are in the United States
- We do not knowingly collect the personal data of children under 13 (COPPA). If we learn of it we destroy the data without delay.
- The Company does not sell personal data and does not share it for targeted advertising. We use no third-party cookies for advertising or analytics (Article 9).
- Whether state laws such as California's apply depends on the size of the business. If a point comes where they apply, we will amend this article and tell you before it takes effect.
15-2-3. If you are in another country
If the law of your country of residence grants broader rights than this policy, those rights prevail. The rights in Article 8 can be exercised from anywhere through the same contact point (dev@impactstation.kr).
Article 16 Effective date
This Privacy Policy takes effect on 1 September 2026.