Wavies Technology Consulting
Privacy Policy
Effective date: 2026-05-18
1. Summary
V-Rail is operated by Wavies Technology Consulting, a Korean sole proprietorship (사업자등록) based in Seoul, Republic of Korea. We process the URL and description you submit, your email, your payment method choice, and limited operational telemetry, in order to deliver the analysis SKU you purchased. We do not sell data. We do not share with advertisers. You retain GDPR / CCPA / PIPA rights including Access, Erasure, Rectification, Portability, Restriction, and Objection. Detailed retention tiers are in §4 below.
2. Data We Collect
- Customer-submitted: the business URL and description you enter at checkout or in the product; your email captured at checkout-complete OR via magic-link claim; SKU selected; payment method (Card via PayPal or Bank transfer via Airwallex).
- Automatically collected: IP address (for rate-limiting and fraud detection), browser user-agent, and request timestamps.
- Payment provider passthrough: PayPal payer email (Card path) or Airwallex transfer reference (Bank-transfer path), received via provider APIs. V-Rail does NOT store card numbers, CVV, or full bank details.
- Analytics: none. We run no analytics or advertising trackers — no cookie banner required. Should we introduce analytics, it will be cookieless and this policy will name the processor before it goes live.
Files you upload (CRM and sequencer exports)
When you upload a CRM or sequencer export, the file is read and analysed entirely inside your browser. It is not uploaded to us. We do not operate an endpoint that could receive it — no route in this application accepts a file upload. That is a property of how the application is built, not a setting we could change without rebuilding it.
Nothing from the file is transmitted while the analysis runs. If — and only if — you press the explicit save button, we receive exactly the following: five coarse band values (contacts_per_deal_band, sender_ratio_band, reply_to_close_band, cohort_n_band, deal_size_band), your email address, the surface you saved from, and your two consent choices. Deal names, monetary amounts, contact names and addresses, message text, company names, dates, and per-deal rows are not transmitted, and the receiving endpoint rejects any field outside that list rather than storing it.
These band values are not anonymous. They are stored in the same record as your email address, which means they are personal data attributable to you, and every right in §7 applies to them. We say this plainly because a coarse band can look like an anonymous statistic and it is not one here.
We run no third-party analytics, advertising, session-replay, or error-reporting scripts on any page, so no such script observes the file, the page, or what you type.
3. Why We Process It (Legal Basis)
- Contract performance (GDPR Article 6(1)(b)) — delivering the purchased analysis SKU.
- Legitimate Interest (GDPR Article 6(1)(f)) — fraud prevention, rate-limiting, audit logging, and B2B prospect enrichment within the documented analysis pipeline.
- Legal obligation (GDPR Article 6(1)(c)) — tax recordkeeping, dispute resolution, and other statutory requirements under Republic of Korea law.
4. Data Retention
- Customer-submitted analysis inputs (URL, description): retained 90 days in active systems after analysis delivery, then deleted. Retained in encrypted backups for 1 year for dispute resolution / Refund-on-Failure verification, then purged.
- Account data (email, portal_user_id linkage): retained while account is active. On account deletion (DSAR Erasure request): purged within 30 days from active systems; 1-year backup retention for legal obligation.
- Payment data (PayPal payer email, Airwallex merchant_order_id, invoice records): retained 5 years per Republic of Korea Framework Act on National Taxes Article 85-3 and 7 years per Republic of Korea Act on the Consumer Protection in Electronic Commerce Article 6 — whichever is longer applies. Inaccessible to V-Rail operational systems; retained in compliance archive only.
- Analysis outputs (PPTX reports, lead lists, copy assets, scoring results): retained for as long as your account exists, so you can re-download what you paid for — matching the commitment in Terms §7. They are not swept on an age timer. You can have them deleted at any time under §7 below, and we act on that request.
- Logs and analytics: retained 90 days. Aggregated metrics (counts, medians, no personally identifying data) retained indefinitely.
Where the automation actually stands. The periods above are the retention targets we hold ourselves to, and we would rather be precise about how they are enforced than let you assume more than is true. Deletion is currently carried out deliberately rather than by a background job: the purge mechanism is built and classifies every table we hold, but it runs in report-only mode and is armed by a person, not on a timer. Records we are legally required to keep — payment and settlement history under the statutes in the third bullet above — are excluded from it in code, not by configuration, so a privacy purge cannot breach a tax-retention duty. Do-not-contact records are never deleted at all, because erasing one would silently re-permit the outreach it exists to stop.
This policy and our Terms (§7) previously disagreed about how long purchased deliverables last — this page said one year, the Terms said for the life of your account. They now agree on the second, because that is what you were promised when you paid, and the retention mechanism no longer applies an age timer to those records. Deletion on request still reaches them immediately under §7 below.
5. Sub-processors
We share data only with the following sub-processors, strictly to deliver the Service:
- PayPal — card payment processing (Card path)
- Airwallex — bank-transfer payment processing (Bank-transfer path)
- Resend — transactional email delivery (magic links, delivery confirmations)
- Supabase — data hosting infrastructure (Postgres + auth)
- Firebase / Google Cloud — application hosting (Cloud Run)
- Crustdata — B2B prospect enrichment (when triggered by analysis pipeline); DPA signed 2026-04-28
- Anthropic — AI generation of analysis, outreach copy, and reports. Where a deliverable concerns a specific business contact, that contact’s name, job title, and company name are included in the request
- BounceBan — email deliverability verification; the email address being verified is sent to them
- Leonardo.ai — image generation for report visuals (prompt text only; no contact data)
- SMTP email relay — operational notifications (order, payment, and alert emails). Our transactional email for magic links and delivery confirmations runs through Resend, listed above; this separate relay handles operational mail
We do NOT sell data. We do NOT share with advertisers or data brokers.
6. International Transfers
Data may be processed in: Republic of Korea (primary operations), United States (Supabase US region, Firebase US region, PayPal global infrastructure, Anthropic), and European Union (Airwallex EU). Standard Contractual Clauses (SCCs) apply where required by GDPR / UK GDPR / PIPA.
We have not yet confirmed the processing region for three recipients — BounceBan, Leonardo.ai, and our operational SMTP relay. We are stating that openly rather than listing a country we have not verified, and this section will name them once confirmed.
7. Your Rights (GDPR / CCPA / PIPA)
- Access — request a copy of your personal data.
- Erasure (Right to be Forgotten) — subject to the retention caveats in §4.
- Rectification — correct inaccurate data.
- Portability — receive your data in a portable format.
- Restriction of processing.
- Objection to processing under the Legitimate Interest legal basis.
- Opt-out of automated decision-making— note: V-Rail’s best-fit buyer scoring and analysis outputs are automated but are advisory in nature. The Customer remains the final decision-maker for any business action taken on V-Rail’s outputs (including but not limited to lead qualification, outreach targeting, copy adoption, or account prioritization). V-Rail’s outputs do not produce legal effects or similarly significant effects on the Customer’s own legal status within the meaning of GDPR Article 22.
DSAR fulfillment SLA: 30 days from receipt. To exercise any right above, email privacy@vrail.io or maxie@vrail.io.
8. Children
V-Rail is a B2B tool intended for businesses. We do not knowingly process data from anyone under 18. Accounts must represent a business entity.
9. Cookies
We run no analytics or advertising trackers, so no cookie banner is required. We do not use advertising cookies. Strictly-necessary cookies may be used for session management (NextAuth) when you sign in. If we later add analytics it will operate in cookieless mode, and this policy will name the processor before it goes live.
10. Changes to This Policy
Material changes are notified by email to active customers and by posting an updated effective date on this page. Privacy version effective 2026-05-18.
11. Contact
Privacy questions: privacy@vrail.io
Operator: Wavies Technology Consulting
Business Type: Korean sole proprietorship (사업자등록)
Business Registration Number: 492-40-01067
Jurisdiction: Republic of Korea
Operator location: Seoul, Republic of Korea
Contact: maxie@vrail.io
California Residents — CCPA / CPRA Opt-Out
California residents may exercise their rights to know, delete, correct, or opt out of sale/sharing of personal information by emailing privacy@vrail.io. Include your name, the email associated with your account (if any), and the nature of your request (delete personal information, do not sell/share, access my data, or correct my data). We respond to verified requests within 45 days as required by Cal. Civ. Code §1798.130. The opt-out anchor URL #ccpa-opt-out resolves to this section.