Effective September 7, 2026 · Controller: Seonbae · Contact: admissions@seonbaetutor.com
1. Purposes, data, and retention
Seonbae processes the minimum personal information needed for the purposes below. Raw passwords are not stored in Seonbae's profile database. Supabase Auth manages salted password hashes.
| Area | Information | Purpose | Retention |
|---|---|---|---|
| Membership and account | Name, email, mobile number, account type, password hash or Google authentication identifier, verification status, consent time, and policy version | Identification, authentication, role based portal access, secure account recovery, password reset, and misuse prevention | Until membership withdrawal or account deletion, unless law requires longer retention |
| Portal, lessons, and consultations | Member role, linked family accounts, schedules, subjects, tutor, notes, Zoom meeting identifiers and status, participant name and email, join and leave times, session duration, completion count, and lesson recordings | Portal and consultation delivery, authorization, scheduling, review, lesson quality and safety, attendance, usage records, technical support, and dispute handling | For the service period and one year after the lesson or consultation relationship ends, or until an active dispute is resolved |
| Student and tutor chat | Sender, conversation, message, sent time, and read time | Lesson preparation, learning communication, and handling disputes or misuse | One year after the lesson relationship ends, or until an active dispute is resolved |
| Enquiries | Name, email or messenger account, curriculum, subject, goals, and enquiry details supplied by the sender | Answering enquiries, tutor matching, and complaint handling | One year after the enquiry ends, or through the contract and applicable statutory retention period if it leads to a contract |
| Automatically generated data | Essential authentication cookies, access time, IP address or one way hashed identifier, browser and device data, error logs, and security logs | Session continuity, request limits, security, and incident response | Rate limit hashes within two days of the final request, cookies through the session or persistent login period, and security logs normally within 90 days unless provider settings or law require longer |
Where Korean consumer protection law applies, contract and payment records may be retained for five years, complaint and dispute records for three years, and display or advertising records for six months.
2. Consent
At sign up we separately explain the purpose, information, retention period, and right to refuse before obtaining express consent for the name, email, mobile number, and verification and consent records. You may refuse, but account creation can be unavailable because this information is required for identification and recovery.
We do not currently request marketing consent. Any future marketing consent will be separate and optional.
4. Processors and overseas transfers
We use service providers to perform contracts and operate the service securely. Transfers occur through encrypted connections when the relevant service is used.
| Provider | Location | Information and purpose | Timing and method | Retention |
|---|---|---|---|---|
| Supabase, Inc. and disclosed subprocessors | India, Mumbai region, and the United States, Singapore, or other support locations | Account, profile, lesson data, authentication cookies, and logs for database, authentication, and security operations | Encrypted transfer during sign up, login, and portal use | Until account deletion or the processing contract ends, with backups removed on the provider's limited schedule |
| Vercel Inc. and subprocessors | United States and countries containing global edge infrastructure | IP address, request data, error logs, and security logs for hosting, delivery, and incident response | Encrypted transfer when the website is accessed | As needed for service operation and security, or until the processing contract ends |
| Google LLC | United States and countries where Google operates servers | Google account name, email, authentication identifier, authentication and reset email content, and delivery records for Google authentication, SMTP email, and web fonts | Encrypted transfer during Google authentication, email delivery, or a font request | Until account deletion, disconnection, or the provider's applicable retention period |
| Zoom Communications, Inc. and disclosed subprocessors | United States and countries where Zoom operates services | Display name, meeting and participant identifiers, email, attendance times, transmitted audio and video, and lesson recordings for online lessons, review, meeting security, lesson quality and safety, attendance, support, and dispute handling | Encrypted transfer when a user enters a Zoom lesson or a meeting event occurs | Lesson recordings, meeting details, and attendance information remain for one year after lessons end, or for Zoom's contractual or statutory period. An active dispute may extend retention until it is resolved |
| jsDelivr operators and CDN providers | Countries containing global CDN nodes | IP address and browser request data for Pretendard web font delivery | Encrypted transfer when a page loads | The limited period set by CDN security and operation policies |
You may object to an overseas transfer, but authentication and hosting are necessary to provide accounts and the portal. Contact our privacy team to object or ask a question.
The browser may request camera and microphone permission for a Zoom lesson, and these devices work only when the user allows access. Seonbae records online lessons by default for review and a safe learning environment. Students and guardians are informed of the purpose, use, and retention period before the first lesson, and we obtain any consent required by law. Recordings are retained for one year after the lesson relationship ends, or until an active dispute is resolved.
5. Deletion
When a purpose is fulfilled or retention expires, we delete data promptly in a way that makes restoration impracticable. Electronic data is logically deleted and permanently removed after the backup cycle. Paper records, if any, are shredded or incinerated.
6. Your rights
You or a lawful representative may request access, correction, deletion, restriction, withdrawal of consent, or account deletion. Standard members can delete an account from My Page after confirming their identity, or may email us. Statutory retention can limit a deletion request, in which case we explain why.
8. Security measures
- Password hashing and encrypted transport
- Role based access control and database row level security
- Minimal administrator privileges and access scope
- Authentication and security log review, backups, and vulnerability response
- Regular review of processor safeguards and service settings
9. Children under 14
An account for a student under 14 must be created and managed by a legal guardian. If we need to collect information directly from a child under 14, we notify the guardian and obtain verifiable consent.
10. Privacy contact and remedies
Privacy team: Seonbae Operations
Email: admissions@seonbaetutor.com
For privacy complaints in Korea, you may also contact the Personal Information Infringement Report Center at 118 or the Personal Information Dispute Mediation Committee at 1833 6972.
11. Policy changes
We announce changes at least seven days before they take effect. Materially adverse changes are announced at least 30 days in advance, and renewed consent is obtained where required.