← Home

Privacy Policy

Itdasy — operated by Y2do
Effective Date: April 22, 2026
Last Updated: April 22, 2026
Operator: Y2do · Business Registration No. 179-36-01681 · Representative: Yeonjun Kang
Contact: contact@itdasy.com
Original Language: Korean (see Korean version). This English version is for reference; the Korean original prevails in case of discrepancy.

Y2do ("Company") recognizes the importance of the personal information of Itdasy ("Service") users and establishes this Privacy Policy in accordance with the Personal Information Protection Act of the Republic of Korea (PIPA) and related laws.

1. Information We Collect and Purpose

1-1. Member (salon owner) data

TypeItemsPurposeRetention
RequiredEmail, hashed password, nameAuthentication, supportUntil account deletion
OptionalShop name, address, phone, Instagram handle, industryAI caption personalizationUntil account deletion
Auto-collectedIP, device info (model/OS), usage logs, cookiesSecurity, quality improvement1 year
BillingApp Store/Play transaction IDsSubscription status, refunds5 years (e-commerce law)

1-2. End-customer data (processed on behalf of salon owners)

Information entered by salon owners about their own customers is treated as entrusted processing on behalf of the owner as controller. Salon owners are responsible for obtaining valid consent from their end-customers before entering data into Itdasy.

2. Third-Party Entrustment and International Transfer

RecipientCountryPurposeData
Google LLCUnited StatesAI generation (Gemini API), analyticsPseudonymized customer labels (e.g., "Customer#1"), booking times, revenue amounts, service names, caption text
Meta Platforms, Inc.United States / IrelandInstagram OAuth, post publishing, tone analysisInstagram user ID, public posts, access tokens
Railway App, Inc.United StatesServer hosting (Docker)All service data (encrypted at rest)
Supabase, Inc.United StatesManaged Postgres databaseAll DB records (encrypted)
Cloudflare, Inc.United StatesImage CDN and R2 storageUploaded photos/videos
Replicate, Inc. / Remove.bgUnited States / GermanyAI image processing (background removal)Uploaded photos (discarded immediately after processing)

2-1. Consent for cross-border transfer

Explicit opt-in consent is collected at sign-up via a checkbox. Users may withdraw consent from the app settings; AI features will be disabled but core features remain available.

2-2. Pseudonymization

Before any call to external AI services (e.g., Google Gemini), customer identifiers are replaced with pseudonyms (e.g., "Customer#1"). Per Google Gemini API terms, input data is not used to train models.

3. Retention and Deletion

4. Your Rights

5. Security Measures

6. Cookies and Tracking

We do not use third-party advertising or cross-site tracking cookies. Only first-party session tokens (localStorage), preference settings, and offline cache are used. All can be cleared via OS/browser settings.

6-bis. Automated Decision-Making (AI Disclosure)

The Service uses AI (Google Gemini API) for: caption suggestions, chat assistant drafts, retention risk scoring. These are advisory only and do not produce legal or financial effects without user confirmation. Users may disable AI features at any time. Inappropriate AI output can be reported via the in-app 🚩 button; we review within 24 hours.

7. Data Protection Officer

Users may also contact the Korean Personal Information Dispute Mediation Committee (+82-1833-6972, kopico.go.kr) or KISA Privacy Complaint Center (118, privacy.kisa.or.kr).

8. Children's Privacy

The Service is not intended for children under 14. If we learn that a child under 14 has registered, we will immediately delete the account and all related data. For children under 14 requiring access, verifiable parental consent is required.

9. Data Breach Notification

In the event of a data breach, affected users will be notified via email and in-app notice within 72 hours, including details of what was leaked, mitigation steps, and contact information for reporting. Breaches involving 1,000+ users are reported to the Personal Information Protection Commission and KISA.

10. Changes to this Policy

Material changes (new entrustment, expanded collection, longer retention) will be notified at least 30 days before taking effect, and re-consent will be requested where applicable. Other changes will be notified at least 7 days in advance via in-app announcement and email.

VersionEffectiveChanges
v1.02026-04-22Initial publication — full PIPA compliance framework
v1.12026-04-22Added GDPR (EU/UK), CCPA/CPRA (California), LGPD (Brazil), APPI (Japan), PIPEDA (Canada), Australia Privacy Act regional notices

11. Notice to EU/EEA and UK Residents (GDPR / UK GDPR)

11-1. Controller and Contact

11-2. Legal Bases for Processing (Art. 6)

PurposeLegal Basis
Account creation, authentication, service deliveryArt. 6(1)(b) — Contract performance
Billing (IAP transaction records)Art. 6(1)(b) Contract; Art. 6(1)(c) Legal obligation (tax)
AI processing via Google Gemini (captions, assistant)Art. 6(1)(a) — Explicit opt-in consent at signup
Cross-border data transfer to US providersArt. 6(1)(a) Consent + Art. 46 SCCs
Security, fraud prevention, error monitoringArt. 6(1)(f) — Legitimate interest (service integrity)
End-customer data entered by salon ownersProcessor role under Art. 28 — owner as controller, Y2do as processor

11-3. Your Rights under GDPR / UK GDPR

We respond to all verified requests free of charge within 30 days.

11-4. International Data Transfers (Chapter V)

11-5. Supervisory Authorities (non-exhaustive)

12. Notice to California Residents (CCPA / CPRA)

12-1. Categories of Personal Information Collected (last 12 months)

Category (§1798.140)Collected?SourcePurposeDisclosed to
A. Identifiers (name, email, user ID)YesYouAccount, serviceProcessors (Supabase, Railway)
B. §1798.80 customer recordsYesYouBilling, supportApple/Google (IAP); processors
D. Commercial info (purchase history)YesApple/Google storesBilling, subscriptionApple, Google
F. Internet/network activity (error logs)LimitedDeviceSecurity/debugSentry
G. GeolocationNo
I. Professional/employmentYes (shop info)YouPersonalizationProcessors
K. Inferences (retention risk)LimitedYour usageChurn alertsNot shared
L. Sensitive Personal Info (SSN, precise geo, biometric, health, genetic, religion, union, sex life)No

12-2. "Do Not Sell or Share My Personal Information"

We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. A "Do Not Sell or Share" link is therefore not required under §1798.135. If our practices change, we will update this Policy and provide an opt-out in the app.

12-3. Your CCPA / CPRA Rights

Exercise rights: email contact@itdasy.com with subject "CCPA Request — [right]". We verify identity by email confirmation and respond within 45 days.

12-4. Shine the Light (Cal. Civ. Code §1798.83)

We do not disclose PI to third parties for their direct marketing, so no such disclosure is required.

12-5. Minors

We do not knowingly collect PI from users under 16 without affirmative consent (CPRA). Users under 14 are prohibited from registering (see Section 8).

13. Notice to Brazilian Residents (LGPD — Law 13.709/2018)

You have rights analogous to GDPR — confirmation, access, correction, anonymization, portability, deletion, information on sharing, and revocation of consent. Exercise via contact@itdasy.com. Complaints: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd.

14. Notice to Japanese Residents (APPI — 個人情報の保護に関する法律)

15. Notice to Canadian Residents (PIPEDA)

We process in accordance with PIPEDA and applicable provincial laws (Quebec Law 25, Alberta PIPA, BC PIPA). Rights of access, correction, and withdrawal of consent. Complaints: Office of the Privacy Commissioner of Canada — priv.gc.ca.

16. Notice to Australian Residents (Privacy Act 1988)

Handled per the 13 Australian Privacy Principles (APPs). Complaints: OAIC — oaic.gov.au.

17. Children's Privacy — Multi-jurisdictional

18. Cookies, Tracking, and Consent

We use only strictly necessary first-party storage to operate the service (session JWT, preference settings, offline cache). We do not use cross-site tracking cookies, advertising identifiers, or third-party analytics for profiling. For EU/EEA/UK users, we present a consent banner at first launch for optional items such as crash-reporting telemetry (Sentry). Declining does not affect core functionality.

19. Security — International Standards

The original text of this policy is in Korean. This English translation is provided for convenience only. In case of any discrepancy, the Korean version shall prevail.

Last updated: April 22, 2026 (v1.1).