PAEEK · InvenQ

InvenQ Privacy Policy

Version 2026.09.21.1

Version 2026.09.21.1 · Published and effective September 21, 2026

Paeek processes InvenQ users’ information only to the extent necessary and explains its processing practices and users’ rights transparently.

1. Purposes and legal basis for processing personal information

Paeek (the “Company”) processes personal information to perform its service agreement with members, authenticate members and social accounts, provide group inventory and task collaboration, verify purchases and manage paid subscription entitlements, handle inquiries, provide security and notifications, and improve the service.

Information required for registration and core features is processed to enter into and perform a contract under Article 15(1)(4) of the Republic of Korea’s Personal Information Protection Act and in accordance with the mandatory collection and use information acknowledged by users. Optional usage analytics information is processed with users’ consent.

2. Personal information processed

3. How information is collected

Information is collected during registration, Google or Apple sign-in and account linking, in-app entry, uploads and inquiries, group collaboration, email verification, Google Play or App Store purchases, restoration and verification, store server notifications, and administrator responses. Access, security, push and subscription information may be generated or transmitted automatically while using the app, servers and integrated providers.

During Apple sign-in, the Company verifies Apple-issued single-use authorization codes and identity tokens and obtains and processes refresh tokens. The camera and photo library are used only for barcode recognition and uploading images selected by users. Contacts, precise location and microphone information are not collected.

4. Retention and use periods

5. Disclosure to third parties and sharing within groups

As a rule, the Company does not sell or disclose users’ personal information to third parties. Where there is a legal basis or separate user consent, the recipient, purpose, data categories and period will be explained in advance.

When a user joins a group, their nickname, profile photo, role and inventory and work records created in that group are visible to authorized members of the same group. Users should check the group and inviter before joining.

6. Processing providers and external integrations

The Company uses the providers below for parts of the work necessary to provide the service and checks requirements concerning protection measures and prohibition of processing for other purposes.

7. Processing locations and international transfers

The AWS API and database services, S3 image storage and SES email delivery operate in the Seoul region of the Republic of Korea. Information may be transferred to the Republic of Korea when users abroad use the service. The integrations below transfer information over encrypted networks when their features are used and process it under each provider’s security policies and contractual terms.

Users may refuse related international transfers by not choosing Google or Apple sign-in, Google Drive, store subscriptions, push notifications or optional analytics, or by withdrawing permissions or consent in provider, device or app settings where available. This may restrict those features, subscription status checks or restoration. Existing payment records may remain for statutory retention periods.

AWS server, storage and email processing is necessary for accounts and core service provision. Refusing this processing prevents use of the service; users may terminate the service agreement through in-app account deletion or customer support. Users who do not wish Shorebird update information to be processed may stop using the app by deleting it, in which case security and feature updates cannot be provided.

8. Google Drive integration

Google Drive integration uses the limited drive.file scope to access only files explicitly selected by the user. The Company does not arbitrarily browse the user’s entire Drive file list.

Selected Excel files are processed temporarily in InvenQ server memory for import validation and registration; originals are not separately stored. Google account connections and file permissions may be revoked in Google account settings.

9. Deletion procedures and methods

Electronic personal information is deleted using methods that make recovery difficult when its retention period ends or its processing purpose is fulfilled. Paper documents, if any, are shredded or incinerated.

On account deletion, email, login and social authentication information, nickname, profile image and push tokens are removed from the active account. If an Apple account is linked, encrypted refresh tokens are processed separately to request Apple authorization revocation and retry failures, then destroyed when that purpose is fulfilled. Payment records subject to statutory retention are kept separately for the relevant period. Inventory and work histories shared with other members identify the author as “Deleted user”; personal contributions such as free-text comments are deleted or de-identified.

10. Rights of users and legal representatives and how to exercise them

Users may request access, correction, deletion, restriction of processing and withdrawal of consent. Profile changes, optional analytics preferences and account deletion are available in the app’s account settings. Other requests may be made through in-app inquiries or customer support email. Apple sign-in authorization can also be managed in Apple account settings.

To preserve owned groups when deleting an account, a group owner may first transfer ownership to another member. By explicitly choosing the relevant option, the owner may instead delete owned groups and their shared data together and proceed immediately with account deletion. An active store subscription does not block account deletion, but deleting an account alone does not cancel App Store or Google Play automatic renewal. To avoid further charges, users may open store subscription management from the app and cancel first. The Company may request additional verification where identity verification is necessary and will explain any restrictions imposed by applicable laws.

Privacy requests: eovkf2040@gmail.com

11. Security measures

12. Entering other people’s information, including business contacts

When group users enter another person’s personal information, such as a business contact’s name or contact details, they must secure lawful authority and the necessary basis, including notices or consent, to enter and share it. Acting as a processor for service provision, the Company stores this information encrypted according to the group’s instructions and displays it to authorized group members.

13. Automatically processed information and optional analytics

The service may automatically process device, app and access information to maintain sign-in and provide security, push notifications and updates. It does not collect advertising identifiers or information for personalized advertising.

Firebase Analytics analysis of screen and feature usage is enabled only with optional consent. Core features remain available without this consent, and users may change their choice at any time in account settings.

14. Children under 14

The Company does not provide account registration services for children under 14. If it discovers that such a child has registered, it will restrict the account and promptly delete the relevant personal information or process it as required by applicable law.

15. Privacy officer and remedies

Privacy officer: Kim Dae-seung (김대승)
Contact: eovkf2040@gmail.com / +82-10-6429-2365

The following are Republic of Korea agencies; short phone numbers are domestic Korean numbers.

16. Changes to this policy

This policy applies from its effective date. Additions, deletions or amendments will be announced through app notices or web pages before taking effect. Renewed consent will be obtained for material changes to users’ rights or where separate consent is necessary.

Publication date: September 21, 2026 / Effective date: September 21, 2026

Business information

Business name: Paeek (페이크) / Representative: Kim Dae-seung (김대승)
Business registration number: 323-60-00789
Mail-order business registration: 2025-서울중구-1159
Address: Room 402, 163 Nangye-ro, Jung-gu, Seoul, Republic of Korea (Hwanghak-dong, Olive 1)
Customer support: eovkf2040@gmail.com / +82-10-6429-2365
Walk-in consultations are not provided. Please use in-app inquiries or email.