Version 2026.09.21.1 · Published and effective September 21, 2026
Paeek processes InvenQ users’ information only to the extent necessary and explains its processing practices and users’ rights transparently.
1. Purposes and legal basis for processing personal information
Paeek (the “Company”) processes personal information to perform its service agreement with members, authenticate members and social accounts, provide group inventory and task collaboration, verify purchases and manage paid subscription entitlements, handle inquiries, provide security and notifications, and improve the service.
Information required for registration and core features is processed to enter into and perform a contract under Article 15(1)(4) of the Republic of Korea’s Personal Information Protection Act and in accordance with the mandatory collection and use information acknowledged by users. Optional usage analytics information is processed with users’ consent.
2. Personal information processed
- Standard registration: login ID, email address, password hash, nickname, and email verification records.
- Google registration and sign-in: unique Google account identifier, email address, display name, and profile photo URL, if provided.
- Apple registration, sign-in and account linking: unique Apple user identifier; actual or private relay email address as chosen by the user; email verification status; private email use and forwarding availability; display name, if provided on first authorization; encrypted refresh token and its hash for revoking Apple authorization; and account linking and authorization revocation status.
- Service preferences: display language and country or region selected by the user or provided by device region settings. These are used for language-specific guidance and email and region-specific notices and documents, and do not determine billing currency or the store country.
- Account and security: hashes of login and refresh session identifiers, access IP address, usage time, and the type, version, consent status, consent time and access environment of consent documents.
- Payments and subscriptions: store and production or test environment; product and plan; purchase initiation request identifier; purchase token or transaction and original transaction identifiers; identifiers linking the applicable group and paying account; purchase and expiration times; automatic renewal, scheduled changes, cancellation, refund, hold and other subscription states; purchase and renewal verification responses and signed transaction and notification information provided by the store.
- Push notifications: device tokens linked to FCM or APNs, device platform, and token refresh time.
- Service use: group membership and roles; items, locations, stock, business partners and stock history; tasks, comments, stocktakes and inquiries; and user-uploaded profile, group and item images.
- Excel: user-selected file names and contents, processed temporarily during import validation and registration; report recipient email addresses, file names and delivery status.
- Optional usage analytics: app instance, device and operating system information, app version, and screen and feature usage events.
3. How information is collected
Information is collected during registration, Google or Apple sign-in and account linking, in-app entry, uploads and inquiries, group collaboration, email verification, Google Play or App Store purchases, restoration and verification, store server notifications, and administrator responses. Access, security, push and subscription information may be generated or transmitted automatically while using the app, servers and integrated providers.
During Apple sign-in, the Company verifies Apple-issued single-use authorization codes and identity tokens and obtains and processes refresh tokens. The camera and photo library are used only for barcode recognition and uploading images selected by users. Contacts, precise location and microphone information are not collected.
4. Retention and use periods
- Account, authentication, profile and social account linking information: until account deletion. Encrypted Apple refresh tokens are processed for the period necessary to maintain account linking and revoke authorization.
- Payment and subscription information: until the purposes of entitlement verification, restoration, renewal, cancellation, refunds and dispute handling are fulfilled. After account deletion, minimal transaction identifiers and status may be retained, with account and group links removed, until necessary store notification processing, duplicate-use prevention, refunds and dispute handling are completed. Where relevant laws apply, contract or withdrawal records and payment or goods supply records are each retained for five years.
- Shared work data, including groups, items, stock, tasks and stocktakes: until the relevant group is deleted. Author identifiers are anonymized on account deletion. If a group owner explicitly chooses to delete owned groups during account deletion, the data is retained until those groups are deleted.
- Inquiries and replies: until inquiry handling and dispute resolution purposes are fulfilled. Consumer complaint and dispute records covered by applicable laws are retained for three years.
- Electronic consent and administrator audit records: for the period necessary to prove consent or actions and handle disputes. Directly identifying information, such as IP addresses and access environments, is removed on account deletion.
- Push tokens, report email delivery records and user-selected original Excel files: until token revocation, completion of delivery or import, or account deletion. Original Excel files are not separately stored on the server.
5. Disclosure to third parties and sharing within groups
As a rule, the Company does not sell or disclose users’ personal information to third parties. Where there is a legal basis or separate user consent, the recipient, purpose, data categories and period will be explained in advance.
When a user joins a group, their nickname, profile photo, role and inventory and work records created in that group are visible to authorized members of the same group. Users should check the group and inviter before joining.
6. Processing providers and external integrations
The Company uses the providers below for parts of the work necessary to provide the service and checks requirements concerning protection measures and prohibition of processing for other purposes.
- Amazon Web Services, Inc.: API and database server operation, file storage (S3), and verification and report email delivery (SES).
- Google LLC: Google sign-in; Google Play purchase and subscription verification and store server notifications; Firebase Cloud Messaging push delivery; Firebase Analytics usage analysis when users opt in; and user-requested Google Drive file selection and transfer.
- Apple Inc.: Apple sign-in, private email relay and authorization revocation; App Store purchase and subscription verification and store server notifications; and push delivery to iOS devices (APNs).
- Code Town, Inc. (Shorebird): checking for and delivering app code updates.
7. Processing locations and international transfers
The AWS API and database services, S3 image storage and SES email delivery operate in the Seoul region of the Republic of Korea. Information may be transferred to the Republic of Korea when users abroad use the service. The integrations below transfer information over encrypted networks when their features are used and process it under each provider’s security policies and contractual terms.
- Amazon Web Services, Inc. — Contact: https://aws.amazon.com/privacy/ — Location: Republic of Korea (Seoul). Data: account, group, service, payment and subscription data, images, email addresses and email contents. Purpose: server, storage and email services. Timing: when using the service or requesting transmission. Retention: until account or group deletion, fulfillment of the delivery purpose, or the applicable statutory retention period.
- Google LLC — Contact: https://support.google.com/policies/answer/9581826 — Location: Google’s global infrastructure, including the United States. Data: Google account identifiers; Google Play purchase tokens, products, subscription status and notification information; push tokens and notification contents; optional analytics; and user-selected Drive files. Purpose: authentication, payment and subscription verification, push, analytics and Drive integration. Timing: feature use and receipt of store notifications. Retention: until fulfillment of each feature’s purpose or account deletion, and for periods under Google’s policies.
- Apple Inc. — Contact: https://www.apple.com/legal/privacy/contact/ — Location: Apple’s global infrastructure, including the United States. Data: Apple user identifiers, actual or private relay email addresses and names supplied by users, authorization codes, identity and refresh tokens, App Store transaction identifiers, products, subscription status, signed transaction and notification information, and iOS device tokens and notification contents. Purpose: Apple sign-in, private relay, authorization revocation, payment and subscription verification, and iOS push delivery. Timing: sign-in, account linking, purchase, restoration, verification, store notifications, account deletion and notification delivery. Retention: until fulfillment of each feature’s purpose or account deletion, and for periods under Apple’s policies.
- Code Town, Inc. (Shorebird) — Contact: privacy@shorebird.dev — Location: United States. Data: anonymous device identifiers, IP addresses, and app, version and update metadata. Purpose: checking for and delivering code updates. Timing: app launch and update checks. Retention: until the update delivery purpose is fulfilled or for periods under Shorebird’s policies.
Users may refuse related international transfers by not choosing Google or Apple sign-in, Google Drive, store subscriptions, push notifications or optional analytics, or by withdrawing permissions or consent in provider, device or app settings where available. This may restrict those features, subscription status checks or restoration. Existing payment records may remain for statutory retention periods.
AWS server, storage and email processing is necessary for accounts and core service provision. Refusing this processing prevents use of the service; users may terminate the service agreement through in-app account deletion or customer support. Users who do not wish Shorebird update information to be processed may stop using the app by deleting it, in which case security and feature updates cannot be provided.
8. Google Drive integration
Google Drive integration uses the limited drive.file scope to access only files explicitly selected by the user. The Company does not arbitrarily browse the user’s entire Drive file list.
Selected Excel files are processed temporarily in InvenQ server memory for import validation and registration; originals are not separately stored. Google account connections and file permissions may be revoked in Google account settings.
9. Deletion procedures and methods
Electronic personal information is deleted using methods that make recovery difficult when its retention period ends or its processing purpose is fulfilled. Paper documents, if any, are shredded or incinerated.
On account deletion, email, login and social authentication information, nickname, profile image and push tokens are removed from the active account. If an Apple account is linked, encrypted refresh tokens are processed separately to request Apple authorization revocation and retry failures, then destroyed when that purpose is fulfilled. Payment records subject to statutory retention are kept separately for the relevant period. Inventory and work histories shared with other members identify the author as “Deleted user”; personal contributions such as free-text comments are deleted or de-identified.
10. Rights of users and legal representatives and how to exercise them
Users may request access, correction, deletion, restriction of processing and withdrawal of consent. Profile changes, optional analytics preferences and account deletion are available in the app’s account settings. Other requests may be made through in-app inquiries or customer support email. Apple sign-in authorization can also be managed in Apple account settings.
To preserve owned groups when deleting an account, a group owner may first transfer ownership to another member. By explicitly choosing the relevant option, the owner may instead delete owned groups and their shared data together and proceed immediately with account deletion. An active store subscription does not block account deletion, but deleting an account alone does not cancel App Store or Google Play automatic renewal. To avoid further charges, users may open store subscription management from the app and cancel first. The Company may request additional verification where identity verification is necessary and will explain any restrictions imposed by applicable laws.
Privacy requests: eovkf2040@gmail.com
11. Security measures
- Passwords and InvenQ login refresh tokens are stored as hashes rather than in their original form.
- Refresh tokens needed to revoke Apple authorization are encrypted with a separate encryption key and access is restricted. Purchase tokens, transaction identifiers and store verification information are used only by authorized server processing.
- Production data in transit uses HTTPS; storage is encrypted, and sensitive business partner contact information is encrypted at the application level.
- Group role-based access control, administrator two-step authentication, session controls and audit logs are applied.
- Image storage is private, signed URLs expire, and infrastructure access follows least privilege.
- Reasonable checks are conducted for security updates, recovery from failures and data protection.
12. Entering other people’s information, including business contacts
When group users enter another person’s personal information, such as a business contact’s name or contact details, they must secure lawful authority and the necessary basis, including notices or consent, to enter and share it. Acting as a processor for service provision, the Company stores this information encrypted according to the group’s instructions and displays it to authorized group members.
13. Automatically processed information and optional analytics
The service may automatically process device, app and access information to maintain sign-in and provide security, push notifications and updates. It does not collect advertising identifiers or information for personalized advertising.
Firebase Analytics analysis of screen and feature usage is enabled only with optional consent. Core features remain available without this consent, and users may change their choice at any time in account settings.
14. Children under 14
The Company does not provide account registration services for children under 14. If it discovers that such a child has registered, it will restrict the account and promptly delete the relevant personal information or process it as required by applicable law.
15. Privacy officer and remedies
Privacy officer: Kim Dae-seung (김대승)
Contact: eovkf2040@gmail.com / +82-10-6429-2365
The following are Republic of Korea agencies; short phone numbers are domestic Korean numbers.
- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
- Supreme Prosecutors’ Office: www.spo.go.kr / 1301
- Korean National Police Agency: ecrm.police.go.kr / 182
16. Changes to this policy
This policy applies from its effective date. Additions, deletions or amendments will be announced through app notices or web pages before taking effect. Renewed consent will be obtained for material changes to users’ rights or where separate consent is necessary.
Publication date: September 21, 2026 / Effective date: September 21, 2026
Business information
Business name: Paeek (페이크) / Representative: Kim Dae-seung (김대승)
Business registration number: 323-60-00789
Mail-order business registration: 2025-서울중구-1159
Address: Room 402, 163 Nangye-ro, Jung-gu, Seoul, Republic of Korea (Hwanghak-dong, Olive 1)
Customer support: eovkf2040@gmail.com / +82-10-6429-2365
Walk-in consultations are not provided. Please use in-app inquiries or email.