Wavies Technology Consulting
Privacy Policy
Effective date: 2026-05-18
1. Summary
V-Rail is operated by Wavies Technology Consulting, a Korean sole proprietorship (사업자등록) based in Seoul, Republic of Korea. We process the URL and description you submit, your email, your payment method choice, and limited operational telemetry, in order to deliver the analysis SKU you purchased. We do not sell data. We do not share with advertisers. You retain GDPR / CCPA / PIPA rights including Access, Erasure, Rectification, Portability, Restriction, and Objection. Detailed retention tiers are in §4 below.
2. Data We Collect
- Customer-submitted: the URL and description you enter at our CheckoutForm; your email captured at checkout-complete OR via magic-link claim; SKU selected; payment method (Card via PayPal or Bank transfer via Airwallex).
- Automatically collected: IP address (for rate-limiting and fraud detection), browser user-agent, and request timestamps.
- Payment provider passthrough: PayPal payer email (Card path) or Airwallex transfer reference (Bank-transfer path), received via provider APIs. V-Rail does NOT store card numbers, CVV, or full bank details.
- Analytics: none. We run no analytics or advertising trackers — no cookie banner required. Should we introduce analytics, it will be cookieless and this policy will name the processor before it goes live.
3. Why We Process It (Legal Basis)
- Contract performance (GDPR Article 6(1)(b)) — delivering the purchased analysis SKU.
- Legitimate Interest (GDPR Article 6(1)(f)) — fraud prevention, rate-limiting, audit logging, and B2B prospect enrichment within the documented analysis pipeline.
- Legal obligation (GDPR Article 6(1)(c)) — tax recordkeeping, dispute resolution, and other statutory requirements under Republic of Korea law.
4. Data Retention
- Customer-submitted analysis inputs (URL, description): retained 90 days in active systems after analysis delivery, then deleted. Retained in encrypted backups for 1 year for dispute resolution / Refund-on-Failure verification, then purged.
- Account data (email, portal_user_id linkage): retained while account is active. On account deletion (DSAR Erasure request): purged within 30 days from active systems; 1-year backup retention for legal obligation.
- Payment data (PayPal payer email, Airwallex merchant_order_id, invoice records): retained 5 years per Republic of Korea Framework Act on National Taxes Article 85-3 and 7 years per Republic of Korea Act on the Consumer Protection in Electronic Commerce Article 6 — whichever is longer applies. Inaccessible to V-Rail operational systems; retained in compliance archive only.
- Analysis outputs (PPTX reports, lead lists, copy assets, scoring results): retained 1 year after delivery for re-issuance and dispute resolution. Customer can request earlier deletion via DSAR.
- Logs and analytics: retained 90 days. Aggregated metrics (counts, medians, no personally identifying data) retained indefinitely.
5. Sub-processors
We share data only with the following sub-processors, strictly to deliver the Service:
- PayPal — card payment processing (Card path)
- Airwallex — bank-transfer payment processing (Bank-transfer path)
- Resend — transactional email delivery (magic links, delivery confirmations)
- Supabase — data hosting infrastructure (Postgres + auth)
- Firebase / Google Cloud — application hosting (Cloud Run)
- Crustdata — B2B prospect enrichment (when triggered by analysis pipeline); DPA signed 2026-04-28
We do NOT sell data. We do NOT share with advertisers or data brokers.
6. International Transfers
Data may be processed in: Republic of Korea (primary operations), United States (Supabase US region, Firebase US region, PayPal global infrastructure), and European Union (Airwallex EU). Standard Contractual Clauses (SCCs) apply where required by GDPR / UK GDPR / PIPA.
7. Your Rights (GDPR / CCPA / PIPA)
- Access — request a copy of your personal data.
- Erasure (Right to be Forgotten) — subject to the retention caveats in §4.
- Rectification — correct inaccurate data.
- Portability — receive your data in a portable format.
- Restriction of processing.
- Objection to processing under the Legitimate Interest legal basis.
- Opt-out of automated decision-making— note: V-Rail’s best-fit buyer scoring and analysis outputs are automated but are advisory in nature. The Customer remains the final decision-maker for any business action taken on V-Rail’s outputs (including but not limited to lead qualification, outreach targeting, copy adoption, or account prioritization). V-Rail’s outputs do not produce legal effects or similarly significant effects on the Customer’s own legal status within the meaning of GDPR Article 22.
DSAR fulfillment SLA: 30 days from receipt. To exercise any right above, email privacy@vrail.io or maxie@vrail.io.
8. Children
V-Rail is a B2B tool intended for businesses. We do not knowingly process data from anyone under 18. Accounts must represent a business entity.
9. Cookies
We run no analytics or advertising trackers, so no cookie banner is required. We do not use advertising cookies. Strictly-necessary cookies may be used for session management (NextAuth) when you sign in. If we later add analytics it will operate in cookieless mode, and this policy will name the processor before it goes live.
10. Changes to This Policy
Material changes are notified by email to active customers and by posting an updated effective date on this page. Privacy version effective 2026-05-18.
11. Contact
Privacy questions: privacy@vrail.io
Operator: Wavies Technology Consulting
Business Type: Korean sole proprietorship (사업자등록)
Business Registration Number: 492-40-01067
Jurisdiction: Republic of Korea
Operator location: Seoul, Republic of Korea
Contact: maxie@vrail.io
California Residents — CCPA / CPRA Opt-Out
California residents may exercise their rights to know, delete, correct, or opt out of sale/sharing of personal information by emailing privacy@vrail.io. Include your name, the email associated with your account (if any), and the nature of your request (delete personal information, do not sell/share, access my data, or correct my data). We respond to verified requests within 45 days as required by Cal. Civ. Code §1798.130. The opt-out anchor URL #ccpa-opt-out resolves to this section.