Skip to content

Privacy Policy

Effective 2026-10-15

This English version is provided for convenience. If it differs from the Korean version, the Korean version prevails.

[사업자명] (“we”) publishes this Privacy Policy under Article 30 of the Korean Personal Information Protection Act (PIPA) to explain how we handle personal data in chckmy (chck.my, the “Service”).

1. Purposes

  1. Accounts — identifying you via Google or an email magic link, keeping your account, preventing abuse, sending notices
  2. The Service — creating and publishing short links and link pages, counting and showing clicks
  3. Paid plans — checking subscription status, applying plan limits, handling billing questions
  4. Safety — blocking malicious links, handling reports, responding to security incidents, aggregate statistics

2. Data we collect

CategoryDataHow
Email magic-link sign-in (required)Email address, hashed sign-in verification tokenEntered by you and generated when issuing a sign-in link
Sign-up / sign-in (required)Google account email, name, profile photo (URL), Google account IDProvided by Google with your consent when you sign in
Created by youLink page handle, title, bio and blocks; short links and destination URLsEntered by you
Sign-in records (automatic)IP address, browser user agent, time of accessGenerated when you sign in and while your session is active
Click records (automatic)For visitors who click a short link or link button: country (derived from IP), referrer, device type, timeGenerated on visit. The IP address itself is not stored in click records.
PaymentsPolar customer ID, subscription product, interval and status, payment/renewal datesReceived from Polar. Card details are collected by Polar directly; we never receive them.
Reports (optional)Reporter email, report detailsEntered on the Report page

We do not accept sign-ups from children under 14.

3. Retention

  • Account and Service data: until you delete your account
  • Sign-in records: deleted when the session expires; security access logs up to 3 months
  • Raw click records: deleted after your plan's retention period (30 days on Free); aggregated daily counts until the link or account is deleted
  • Reports: 1 year after resolution

Where Korean law requires, we keep: contract/withdrawal records and payment records for 5 years, consumer complaint records for 3 years (E-Commerce Act), and access logs for 3 months (Protection of Communications Secrets Act).

4. Deletion

We delete personal data without delay (within 5 days) once it is no longer needed. Data we must keep by law is stored separately and deleted when the period ends. Electronic files are deleted irrecoverably; backups are purged on their normal rotation.

5. Disclosure to third parties

We only disclose personal data with your consent or where the law allows (PIPA Articles 17–18). Data sent to Polar for payments is described in Section 6. Link pages and short links are public by design: the handle, title, bio, profile image and links you publish can be seen by anyone.

6. Processors and transfers abroad

Recipient (contact)CountryDataPurposeWhen / howRetention
Cloudflare, Inc. (privacyquestions@cloudflare.com)USA and countries with Cloudflare data centresAll data in Section 2Hosting, database, sign-in email delivery, network and securityContinuously over the network while you use the ServiceUntil account deletion or end of contract
Google LLCUSASign-in request dataGoogle sign-inAt Google sign-inPer Google's privacy policy
Polar Software, Inc. (privacy@polar.sh)USAEmail, name, member ID, selected planMerchant of Record: payments, invoicing, taxes, receiptsAt checkout, over the networkPer Polar's privacy policy and applicable law

If you do not want these transfers, you can choose not to sign up or delete your account. Cloudflare is essential to the Service; Google is used for Google sign-in and Polar for paid plans.

7. Your rights

You may request access to, correction or deletion of, or suspension of processing of your personal data, and withdraw consent at any time. Most of this can be done in the dashboard (edit your profile and links, delete your account); for anything else, email our privacy officer and we will respond within 10 days. You may act through a legal representative or authorised agent with a power of attorney.

8. Cookies

We only use a session cookie to keep you signed in and a language cookie to remember your language. We do not use advertising or tracking cookies. You can block cookies in your browser, but you will not be able to sign in.

9. Security

  • Access to personal data limited to the minimum number of people; internal management plan
  • HTTPS for all traffic, database access controls, Google or email magic-link sign-in (no passwords stored), access logs
  • Data stored in access-controlled Cloudflare data centres

10. Privacy officer

  • Privacy officer: [개인정보 보호책임자 성명]
  • Email: [개인정보 문의 이메일]

11. Remedies

You may also contact the following Korean authorities:

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • Korean National Police Agency: 182 (ecrm.police.go.kr)

12. Changes

This policy applies from 2026-10-15. We announce changes in the Service at least 7 days in advance (30 days for significant changes).